The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.
You can also see and filter all release notes in the Google Cloud console or you can programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your
feed
reader, or add the feed URL directly: https://cloud.google.com/feeds/gcp-release-notes.xml
July 26, 2023
Cloud Data FusionIn the SAP SuccessFactors Batch Source plugin version 1.2.0, fixed an issue causing a null pointer exception when you provide a valid entity name that has more than one expand option separated by a '/'.
Dynamic thread scaling is generally available (GA). Dynamic thread scaling is a part of Dataflow's suite of vertical scaling features.
(2023-R16) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- Version 1.27.2-gke.1200 is now the default version.
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.21.14-gke.18800
- 1.23.17-gke.6800
- 1.23.17-gke.7000
- 1.24.13-gke.2500
- 1.25.8-gke.1000
- 1.25.9-gke.2300
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.7700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
Stable channel
- Version 1.26.5-gke.1400 is now the default version in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.21.14-gke.18800
- 1.23.17-gke.6800
- 1.24.13-gke.2500
- 1.25.9-gke.2300
- 1.26.5-gke.1200
- 1.27.2-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.7700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.25 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.27 to version 1.27.3-gke.100 with this release.
Regular channel
- Version 1.27.2-gke.1200 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.21.14-gke.18800
- 1.22.17-gke.12700
- 1.23.17-gke.7000
- 1.24.14-gke.1200
- 1.25.10-gke.1200
- 1.26.5-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.14100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.8400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.14-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.10-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.26.5-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
Rapid channel
- Version 1.27.3-gke.100 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.21.14-gke.18800
- 1.23.17-gke.7700
- 1.24.14-gke.2700
- 1.25.10-gke.2100
- 1.26.5-gke.2100
- 1.27.2-gke.2100
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.8400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.27 to version 1.27.3-gke.100 with this release.
(2023-R16) Version updates
- Version 1.27.2-gke.1200 is now the default version.
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.21.14-gke.18800
- 1.23.17-gke.6800
- 1.23.17-gke.7000
- 1.24.13-gke.2500
- 1.25.8-gke.1000
- 1.25.9-gke.2300
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.7700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
(2023-R16) Version updates
- Version 1.26.5-gke.1400 is now the default version in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.21.14-gke.18800
- 1.23.17-gke.6800
- 1.24.13-gke.2500
- 1.25.9-gke.2300
- 1.26.5-gke.1200
- 1.27.2-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.7700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.25 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.27 to version 1.27.3-gke.100 with this release.
(2023-R16) Version updates
- Version 1.27.3-gke.100 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.21.14-gke.18800
- 1.23.17-gke.7700
- 1.24.14-gke.2700
- 1.25.10-gke.2100
- 1.26.5-gke.2100
- 1.27.2-gke.2100
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.8400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.15-gke.1700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.27 to version 1.27.3-gke.100 with this release.
July 25, 2023
Anthos Service MeshUpdated:2023-07-26
1.17.5-asm.0 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-021 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
Updated:2023-07-26
1.16.7-asm.0 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-021 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
Updated:2023-07-26
1.15.7-asm.23 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-021 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
FEATURE
Release 1.14.7
Anthos clusters on bare metal 1.14.7 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.7 runs on Kubernetes 1.25.
Functionality changes:
Audit logs are compressed on the wire for Cloud Audit Logs consumption, reducing egress bandwidth by approximately 60%.
Upgraded local volume provisioner to v2.5.0.
Upgraded snapshot controller to v5.0.1.
Deprecated v1beta1 volume snapshot custom resources. Anthos clusters on bare metal will stop serving v1beta1 resources in a future release.
Fixes:
Fixed an issue where the smart default didn't work for
gke-metrics-agent.Fixed an issue where the apiserver could become responsive during a cluster upgrade for clusters with a single control plane node.
Fixed an issue where audit logs were duplicated into the offline buffer even when they are sent to Cloud Audit Logs successfully.
Fixes:
The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
Cloud Composer 2 is now available in Paris (europe-west9).
The global external HTTP(S) load balancer now supports a configurable client HTTP Keepalive Timeout. The client HTTP keepalive timeout represents the maximum amount of time that a TCP connection can be idle between the (downstream) client and the target HTTP/S proxy.
For details, see
This capability is available in General Availability.
Generally available: You can modify the description, schedule frequency, retention policy, or labels for a snapshot schedule instead of creating a new snapshot schedule. For more information, see Change a snapshot schedule.
When you run multiple SDK processes on a shared Dataflow GPU, you can improve GPU efficiency and utilization by enabling the NVIDIA Multi-Process Service (MPS).
Kubernetes control plane logs and Kubernetes control plane metrics are now available for GKE Autopilot clusters with control plane version 1.22.0 and later and 1.22.13 and later, respectively. You can now configure Autopilot cluster to export logs and certain metrics emitted by the Kubernetes API server, scheduler, and controller manager to Cloud Logging and Cloud Monitoring.
Event-driven transfers are now generally available (GA).
Event-driven transfers provide serverless, real-time replication from AWS S3 to Cloud Storage, and between Cloud Storage buckets. With this new capability, you can accelerate your event-driven analytics pipeline, enable automatic replication across Cloud Storage buckets, create a backup copy of data in a different region or project, or perform live migration.
Learn more about Event-driven transfers.
July 24, 2023
Apigee XOn July 24, 2023, we released an updated version of Apigee X.
Public preview of Apigee gRPC passthrough
Apigee's new gRPC proxy passthrough functionality provides the ability to create proxies which receive gRPC client requests and pass them through to a gRPC target server.
For information, see Creating gRPC API proxies.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.30.1 (2023-07-18)
Dependencies
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.23.0 (#2791) (940301b)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.27.0 (#2792) (c791066)
2.30.0 (2023-07-17)
Features
- Add missing storage related fields to Table, TableInfo and StandardTableDefinition (#2673) (e3003f4)
- Add support for Search statistics (#2787) (344f695)
Dependencies
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.22.0 (#2777) (078f244)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.26.0 (#2778) (2ee52c9)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.13.0 (#2786) (dd14eee)
- Update github/codeql-action action to v2.20.1 (#2766) (2014613)
- Update github/codeql-action action to v2.20.4 (#2784) (e886f5f)
- Update ossf/scorecard-action action to v2.2.0 (#2775) (688b2a0)
Python
Changes for google-cloud-bigquery
3.11.4 (2023-07-19)
Bug Fixes
The following Assured Workloads compliance programs now support Certificate Authority Service:
- Australia Regions with Assured Support
- Canada Regions and Support
- Canada Protected B
- Israel Regions and Support
- US Regions and Support
See supported products for more information.
Cloud Bigtable is available in the europe-west12 (Turin) and me-central1 (Doha) regions. For more information, see Bigtable locations.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigtable
2.25.0 (2023-07-14)
Features
Bug Fixes
- Fix batch mutation limit (#1808) (ed24d4f)
- Update default sample row key attempt timeout to 5 min (#1827) (2f363ef)
Documentation
- Fix formatting for reversed order field example (#1836) (10a0426)
- Increase the maximum retention period for a Cloud Bigtable backup from 30 days to 90 days (#1826) (159fe38)
Dependencies
Python
Changes for google-cloud-bigtable
2.20.0 (2023-07-17)
Features
- Add experimental reverse scan for public preview (d5720f8)
- Increase the maximum retention period for a Cloud Bigtable backup from 30 days to 90 days (d5720f8)
Bug Fixes
Documentation
Internal passthrough Network Load Balancer now supports load-balancing for TCP, UDP, ICMP, ICMPv6, SCTP, ESP, AH, and GRE protocols. To handle multiple protocol traffic, you set the load balancer's forwarding rule protocol to L3_DEFAULT and set the backend service protocol to UNSPECIFIED.
For details, see:
This feature is available in Preview.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-logging
3.15.6 (2023-07-17)
Dependencies
Preview: You can now use SSH-in-browser to connect to TPU VMs.
Added a new Experimental Feature ConfigConnectorAlphaResources that manages the installation and upgrade of Config Connector v1alpha1 CRDs.
You can use the gcloud CLI version 438.0.0 or above to leverage this feature.
To create a Config Controller instance with the feature, run the following command:
gcloud alpha anthos config controller create ${NAME} \
--location ${LOCATION} \
--experimental-features ConfigConnectorAlphaResources
To update an existing Config Controller to enable the feature, run the following command:
gcloud alpha anthos config controller update ${NAME} \
--location ${LOCATION} \
--experimental-features ConfigConnectorAlphaResources
You can now create delivery pipelines, targets, and releases using the Google Cloud console.
You can now configure routeUpdateWaitTime for HTTPRoute resource propagation with GKE/Anthos Gateway API canary deployment.
Google Cloud Deploy now uses Skaffold 2.6 as the default Skaffold version for all target types.
We've made the following improvements to reports for Cloud Marketplace products:
We've added a
solution_namecolumn to Customer Insights reports, which contains the title of the listing that the SKU charge corresponds to. You can use this information to differentiate between identically-named SKUs from different product listings. For more information, visit the Customer Insights report documentation.We've added a Postpay Credits column to Charges and Usage reports, and a
postpay_creditscolumn to Daily Insights reports and Monthly Insights reports. These columns indicate, as a number less than or equal to 0, how much of the amount charged was offset by commitment credits purchased through a private offer with a postpay payment schedule. These applied credits reduce the amount disbursed to you for the charges that they're applied to, as the payout comes from the charge for the commitment SKU. For more information, visit the Charges and Usage report documentation.
In new Autopilot clusters running GKE version 1.27 and later, GKE assigns IP addresses for GKE Services from a Google-managed range: 34.118.224.0/20 by default. With this feature, you don't need to specify your own IP address range for Services. For more information, see Subnet secondary IP address range for Services.
GKE Autopilot supports extended duration Pods from 1.27 or later with the cluster-autoscaler.kubernetes.io/safe-to-evict=false annotation. To learn more, see how to extend the run time of Autopilot Pods.
July 21, 2023
Access ApprovalAccess Approval supports AlloyDB for PostgreSQL in the Preview stage.
On July 21, 2023, we released an updated version of Apigee X.
The Advanced API Security Abuse detection Incident details page now displays unique IP addresses, even if more than one incident corresponds to the same IP address. Previously, the Incident details page could display the same IP address more than once for different incidents.
Also, the Attributes tab of the Incident details page no longer displays the following attributes:
- Top App Key
- Detected Rules
- Top URL
hybrid v1.9.4
On July 21, 2023 we released an updated version of the Apigee hybrid software, v1.9.4.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.9.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 289254725 | Implemented a fix to prevent failure of proxy deployments that include the OASValidation policy. |
| 279712107 | Added the ability to annotate apigee-ingressgateway-manager pods through overrides.yaml file. See istiod.annotations for details. |
| 158132963 | Added improvements to capture relevant target flow variables in trace and analytics in case of target timeouts. |
| Bug ID | Description |
|---|---|
| 290709899 | Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerability: |
| 290829028 | Security fixes for Apigee Connect and apigee-connect-agent and apigee-redis. This addresses the following vulnerabilities: |
Backup for GKE is now available in five new regions: europe-west12, me-west1, me-central1, us-south1, and us-east5.
The e2-medium machine type is now supported as a custom machine type that you can specify in your cloudbuild.yaml build configuration file. For more information, see machineType.
The Cloud Logging agent for Windows version 1-21 is now available. This version has no user-visible changes but upgrades the grpc gem and others to fix vulnerabilities. This also includes the switch to Ruby 3, from version 1-20 of the Logging agent.
Cloud TPU now supports TensorFlow 2.12.1. For more information see the TensorFlow 2.12.1 release notes.
When viewing a span, you can now also view the linked spans. For more information, see View span details.
Cloud Workstations is available in the europe-west12 region (Turin, Italy, Europe). For more information, see Locations.
Generally available: NVIDIA T4 GPUs are now available in the following additional regions and zones:
- Salt Lake City:
us-west3-b
For more information about using GPUs on Compute Engine, see GPU platforms.
cos-105-17412-156-4
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.120 | v23.0.3 | v1.7.2 | v470.199.02(default),v525.125.06 |
Fixed CVE-2023-35001 in the Linux kernel.
Fixed CVE-2023-31248 in the Linux kernel.
Fixed stability issues in the device memory TCP feature.
New Dataproc Serverless for Spark runtime versions:
- 1.1.24
- 2.0.32
- 2.1.11
New Dataproc on Compute Engine image versions, which includes a 2.1.18-ubuntu20-arm image that supports ARM machine types:
- 2.0.70-debian10, 2.0.70-rocky8, 2.0.70-ubuntu18
- 2.1.18-debian11, 2.1.18-rocky8, 2.1.18-ubuntu20, 2.1.18-ubuntu20-arm
Fixed a race condition in Spark startup that could lead to nodes failing to initialize when using premium disk tier.
Update to the Issue release note published on July 19, 2023
We investigated this issue and are rolling back the --no-enable-insecure-kubelet-readonly-port flag in the gcloud CLI. New or existing clusters where the port is still enabled aren't affected. If you already disabled the port, your cluster will continue to work, but you may notice inconsistency in whether the port is fully disabled on every node of the cluster. We'll publish a release note if we have new updates related to the kubelet read-only port.
Google Cloud's Agent for SAP version 2.3
Version 2.3 of Google Cloud's Agent for SAP is generally available (GA). This version introduces bug fixes for SAP system discovery sending data to Cloud Logging.
For more information, see What's new with Google Cloud's Agent for SAP.
July 20, 2023
Anthos clusters on VMwareAnthos clusters on VMware 1.13.10-gke.42 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.13.10-gke.42 runs on Kubernetes 1.24.14-gke.2100.
- Upgraded VMware vSphere Container Storage Plug-in from 2.6.2 to 2.7.2.
- Added short names for Volume Snapshot CRDs.
The following issues are fixed in 1.13.10-gke.42:
- Fixed an issue that CPv1 stackdriver operator has
--is-kubeception-less=truespecified by mistake. - Fixed an issue that
/etc/vsphere/certificate/ca.crtis not updated after vsphere CA rotation on the Controlplane v2 user cluster control plane machines. - Fixed an issue where audit logs are duplicated into an offline buffer even when they are successfully sent to Cloud Audit Logs.
- Fixed a known issue where
$in the private registry user name would cause admin control plane machine startup failure. - Fixed a known issue where the update operation cannot be fulfilled due to KSA signing key version unmatched.
The following vulnerabilities are fixed in 1.13.10-gke.42:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Ubuntu vulnerabilities:
Windows vulnerabilities:
Release 1.15.3
Anthos clusters on bare metal 1.15.3 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.3 runs on Kubernetes 1.26.
Anthos clusters on bare metal 1.15.3 supports adding the
gkeOnPremAPI section to your admin and user cluster configuration files to
enroll the clusters in the Anthos On-Prem API. Enrolling the clusters in the Anthos On-Prem API lets you
upgrade admin and user clusters using the Google Cloud console or the Google Cloud CLI.
Fixes:
Fixed an issue where the apiserver could become responsive during a cluster upgrade for clusters with a single control plane node.
Fixed an issue where cluster installations or upgrades fail when the cluster name has more than 45 characters.
Fixed an issue where node-specific labels set on the node pool were sometimes overwritten.
Fixed an issue where audit logs were duplicated into the offline buffer even when they are sent to Cloud Audit Logs successfully.
The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
On July 20, 2023, we released an updated version of Apigee X (1-10-0-apigee-6).
| Bug ID | Description |
|---|---|
| 290943249 | Fixed latency issue between Istio and runtime container. |
| 205666368 | Fixed issue with default validation of TLS target endpoint certificates. To enable strict SSL on southbound connections to a proxy target endpoint, add the tag |
| Bug ID | Description |
|---|---|
| 290709899 | Security fix for apigee-runtime. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-redis and apigee-connect-agent. These address the following vulnerabilities: |
| N/A | Security fixes for apigee-connect-agent. These address the following vulnerabilities: |
Connector Event triggers (Preview)
Application Integration introduces Connector Event triggers; specialized triggers that let you invoke an integration based on the event subscriptions created in various business applications using Integration Connectors.
The following Connector Event triggers are available in preview:
For more information, see Connector Event triggers.
Known issues
- Integration fails to publish when duplicate Connector Event triggers are configured
- Event subscription error when an integration containing Connector Event triggers is uploaded
For more information, see Application Integration known issues.
Multivariate time series forecasting with the
ARIMA_PLUS_XREG model in BigQuery ML is now generally available
(GA). This feature lets you perform time series forecasting with extra feature columns. For more information, see the ARIMA_PLUS_XREG information in the end-to-end user journey topic, and try the
multivariate time-series forecasting from Seattle air quality data tutorial.
BigQuery ML has introduced new Explainable AI capabilities for better model explainability:
- You can now use the
ML.EXPLAIN_FORECASTfunction withARIMA_PLUS_XREGmodels. - You can use the updated
ML.EXPLAIN_FORECASTfunction to get explanations of the holiday effect for holidays in time series forecasting models (bothARIMA_PLUSandARIMA_PLUS_XREG). - You can now use the
ML.GLOBAL_EXPLAINfunction with AutoML Tables models for global model explainability. - For Boosted Tree and
Random Forest
models, you can now use the
approx_global_feature_contribtraining option to use fast approximation for global feature contribution computation in model training, and theapprox_feature_contriboption in theML.EXPLAIN_PREDICTfunction to use the fast approximation for local feature contribution computation in model inference.
On July 20, 2023 Blockchain Node Engine added a self-managed nodes section and common setup instructions.
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- BigQuery Migration Service
bigquerymigration.googleapis.com/MigrationWorkflow
Cloud Build repositories (2nd gen) is now generally available. Cloud Build repositories (2nd gen) integrates directly with GitHub, GitHub Enterprise, GitLab, and GitLab Enterprise Edition and comes with end-to-end Terraform support. To learn more, see the Repositories overview page.
Workforce identity federation is generally available (GA) in Cloud Data Fusion.
The Cloud Data Fusion SAP ODP plugin supports extracting data through CDS views.
Apache Hadoop MapReduce is deprecated in Cloud Data Fusion versions 6.7.0 and later (CDAP-18913).
Support for routing your logs through the Log Router of another Google Cloud project is now Generally Available (GA). For more information, see Route logs to supported destinations.
We made improvements to the dashboard building experience:
- Improved the performance
- Simplified the layout and expanded the configurable settings
- Improved the widget drag and drop experience
- Enhanced the text widget
- Unified the chart-configuration experience between dashboards and the Metrics Explorer
For more information, see Add charts and tables to a custom dashboard.
The Cloud Router custom learned routes feature is Generally Available (GA). For more information, see Custom learned routes.
Enterprise Search: Citations
Summary citations are now available in preview. Citations indicate from which search results specific sentences in the summary are taken.
For more information, see Get citations.
Enterprise Search: Ignore adverserial and non-summary seeking queries
You can now configure search requests so that adversarial queries and non-summary seeking queries do not include a summary in the response. This feature is in preview.
For more information, see Ignore adversarial queries and Ignore non-summary seeking queries.
Enterprise Search: Personalize
We have renamed the "Personalize" feature of Generative AI App Builder to "Recommendations". This is a naming change only. There is no change to product functionality.
In GKE version 1.25 and later, there is a bug fix in the Ingress Controller to unset the Cloud Armor Ingress Security Policy when removed from the BackendConfig.
Users who have manually attached the Security Policy to a backend service should no longer use this method and should use the BackendConfig to continue using Cloud Armor Security Policies prior to cluster upgrades to GKE version 1.25 and later.
With this fix, the Ingress Controller will reconcile using the configuration in the BackendConfig, thus unsetting any Security Policies added manually to a backend service.
Pro feature: Add a quick filter
Quick filters provide a flexible, ad hoc way to explore your data. Use quick filters to easily change how the data in the report is filtered without changing the report configuration for other users.
Pro feature: Get a personal report link
A personal report link creates a copy of your report that is only accessible to the person who opens the link. Changes made to either the original or the private report will not affect the other report.
Intervals for time series charts
You can add intervals to time series charts to show how much uncertainty there is in your data. Intervals can be represented as shaded bands (area intervals), boxes, lines, or other shapes, depending on the interval type you specify.
To add an interval to a time series chart, select the Add an interval option in the STYLE section of the properties panel.
Changes to Google Ads creative assets reporting
The Google Ads connector for Looker Studio is aligned with the public Google Ads API for creative assets reporting.
To return accurate results when using Clicks and/or Impressions metrics in combination with creative asset dimensions, be sure to also include Ad Type and Asset ID dimensions in your chart. Otherwise, the chart may show inaccurate results.
Charts that aren't correctly configured will display a message that warns you about the invalid combination of dimensions and metrics.
New Explore topic in the Help Center
You can find content that is related to exploring, analyzing, and filtering your data in this new Explore topic. New and existing content on filters, controls, and chart interactions lives in this topic.
July 19, 2023
Apigee API hubOn July 19, 2023 Apigee API hub released a new version of the software.
Lint result artifacts, or conformance reports, represent how conformant an API is with respect to the specified lint rules. Results in conformance report artifacts attached to an API spec revision are now displayed in the right pane of the API spec revision detail page. One of the following is displayed:
- No information to display.
No style guide conformance information has been generated for this spec. - No issues found.
Style guide conformance scans found no issues with this spec. - Warnings and Errors.
Any errors or warnings are explained.
An indicator also marks the corresponding line in the spec.
See also:
BigQuery can now use search indexes to optimize some queries that contain the equal operator (=), IN operator, LIKE operator, or STARTS_WITH function to compare string literals with indexed data. This feature is in preview.
The Python buildpack now uses gunicorn --bind :8080 main:app as the default entrypoint for all web applications. If you currently use a Procfile, it will continue to work but you are no longer required to configure a Procfile for your projects. Learn more about Python application entrypoints.
Release Notes 6.2.31
Added the ability to write comments on cases that have already been closed.
New API for Logs: Admin users can now retrieve raw python logs directly from the platform using the following API: POST/api/external/v1/logging/python
Release Notes 6.2.31
Importing a custom integration on top of an existing commercial integration causes the connector to not work properly (ID #00243798)
Specific Integration showing incorrect update available (ID #00181718)
SDK call siemplify.current_alert.creation_time returns 0 (ID #00226591)
In rare situations, unable to access several cases via the Platform or via API (ID #00243878)
When changing the Case Stage under the Cases tab, the drop down list of stages does not follow the same numerical order as defined in the Settings (ID #44453181)
Entities that should be internal are created as external if ingested using the environment alias (ID #00225318)
In certain situations, alerts are ingested into the platform for environments that don't exist yet in the platform and as soon as the environments are created - the cases are opened and playbooks run. It is now possible to configure alerts to be dropped if the source environment doesn't exist. (ID #00180834)
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- Network Connectivity
networkconnectivity.googleapis.com/PolicyBasedRoute
- Database migration
datamigration.googleapis.com/PrivateConnection
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
The pricing language for Cloud Logging has changed; however, the free allotments and the rates haven't changed. For more information, see Cloud Logging pricing summary.
The project usage monitoring page has moved to a new URL under the existing project usage page. For more information, see Usage dashboard.
Cloud Deploy has completed Google Cloud data residency requirements.
We've redesigned the Private Offers experience to improve offer creation and management, including the following changes:
- You can fill in information in any order, instead of having to enter it all at once.
- We've added sectional cards with icons that show completion status, so that you can get a high-level overview of an offer from a single page.
- We've added a summary panel showing key changes to deals.
- We've made improvements to increase the product's adaptability and usability.
There's a known issue causing the gcloud CLI to crash when you run the command to disable the insecure kubelet read-only port, as described in Stop using the insecure kubelet read-only port in GKE clusters. We're investigating this issue and will publish an update when it's fixed.
Starting in GKE version 1.27 and gke-metrics-agent version 2.0.0, the memory request and limit of gke-metrics-agent will increase by an extra 60MiB. This change makes the system metrics collection more stable and reliable.
Added support for Creating a Memcached instance that uses a specific IP address range.
Preview stage support for the following integration:
Vertex AI Workbench instances are now available in Preview. Vertex AI Workbench instances combine features from managed notebooks and user-managed notebooks to provide a robust data science solution. Supported features include:
- Idle timeout
- BigQuery and Cloud Storage integrations
- End-user and service account authentication
- VPC Service Controls
- Customer managed encryption keys (CMEK)
- Health status monitoring
- Run notebooks on a schedule
- Dataproc integration
To get started, see Introduction to Vertex AI Workbench instances.
July 18, 2023
AlloyDB for PostgreSQLAlloyDB support for Data Residency is generally available (GA).
AlloyDB now supports setting up resource locations policies that can be used to constrain the location of new in-scope resources.
1.15.7-asm.21 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-019 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.16.6-asm.3 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-019 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
1.17.4-asm.2 is now available for in-cluster Anthos Service Mesh.
This patch release contains the fix for the security vulnerability listed in GCP-2023-019 For details on upgrading Anthos Service Mesh, refer to Upgrade Anthos Service Mesh.
VPC Service Controls support for Batch is generally available (GA).
VPC Service Controls lets you create perimeters that protect the resources and data of Google Cloud services that you explicitly specify. For more information, see Overview of VPC Service Controls and Use VPC Service Controls with Batch.
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- Service Directory
servicedirectory.googleapis.com/Endpointservicedirectory.googleapis.com/Service
Cloud Bigtable change streams are now generally available (GA). A change stream captures changes to data in a table as the changes happen, letting you stream them for processing or analysis. For more information, see Change streams overview.
You can now upgrade log buckets in most regions to use Log Analytics. To determine if the region of a log bucket is supported, see Supported regions.
Cloud SQL now supports default maintenance windows for your instances. With this release, an instance without a user-specified maintenance window is maintained outside of the typical business hours for the time zone that the instance is deployed in.
Cloud SQL now supports default maintenance windows for your instances. With this release, an instance without a user-specified maintenance window is maintained outside of the typical business hours for the time zone that the instance is deployed in.
Cloud SQL now supports default maintenance windows for your instances. With this release, an instance without a user-specified maintenance window is maintained outside of the typical business hours for the time zone that the instance is deployed in.
Spanner supports cascading deletes for foreign keys. For more information, see Foreign key actions.
The gcloud storage command-line tool has changed some of the metadata it returns for buckets and objects, as well as changed the format of some metadata names it returns.
- To output metadata in the form used prior to July 18, 2023, include the flag
--rawin yourlistanddescribecommands for objects and buckets.
gcloud storage GA release 1.3 is now available.
- The 1.3 release adds support for the
rsynccommand, which synchronizes content between a source and destination. - The 1.3 release also adds support for generating signed URLs, managing HMAC keys, calculating bucket sizes and calculating hashes.
cos-97-16919-353-1
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.186 | v20.10.24 | v1.6.21 | v470.199.02 (default),v525.125.06 |
Updated containerd to v1.6.21
Updated app-emulation/docker and app-emulation/docker-cli to v20.10.24.
Updated app-admin/google-osconfig-agent to v20230222.00.
Updated default GPU driver to v470.199.02 and latest GPU driver to v525.125.06. This resolves CVE-2023-25515 and CVE-2023-25516.
Updated open-vm-tools to v12.2.5. This resolves CVE-2023-20867.
Fixed CVE-2023-3609 in the Linux kernel.
Runtime sysctl changes:
- Changed: net.core.bpf_jit_limit: 264241152 -> 528482304
cos-dev-109-17758-0-0
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.1.38 | v23.0.3 | v1.7.2 | v470.199.02(default),v525.125.06 |
Enabled TDX Guest support in the Linux Kernel.
Updated app-emulation/kubernetes to v1.27.3.
Updated oslogin to v20230531.00.
Updated google-osconfig-agent to v20230706.02.
Updated docker-credential-gcr to v2.1.10.
Updated default GPU driver to v470.199.02 and latest GPU driver to v525.125.06. This resolves CVE-2023-25515 and CVE-2023-25516.
Runtime sysctl changes:
- Changed: fs.file-max: 812620 -> 812619
cos-105-17412-156-2
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.120 | v23.0.3 | v1.7.2 | v470.199.02(default),v525.125.06 |
Updated containerd to v1.7.2.
Updated default GPU driver to v470.199.02 and latest GPU driver to v525.125.06. This resolves CVE-2023-25515 and CVE-2023-25516.
Updated open-vm-tools to v12.2.5. This resolves CVE-2023-20867.
Fixed CVE-2023-3609 in the Linux kernel.
cos-93-16623-402-45
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.248.02(default),v470.199.02(R470),v525.125.06 |
Updated default GPU driver to v450.248.02, R470 GPU driver to v470.199.02 and latest GPU driver to v525.125.06. This resolves CVE-2023-25515 and CVE-2023-25516. CVE-2023-25515, CVE-2023-25516.
Fixed CVE-2023-3609 in the Linux kernel.
cos-101-17162-210-56
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.199.02(default),v525.125.06 |
Updated default GPU driver to v470.199.02 and latest GPU driver to v525.125.06. This resolves CVE-2023-25515 and CVE-2023-25516.
Fixed CVE-2023-3609 in the Linux kernel.
Dialogflow CX has launched three new generative AI features. These features are generally available (GA), but access is limited and must be requested:
Also see the blog post announcing these features.
The following Form Parser (pretrained-form-parser-v2.0-2022-11-10) features are Generally Available (GA):
- General field extraction: You can extract 11 different types of entities from documents
- Enhanced checkbox detection
- Internationalization (i18n) support that covers over 200 languages
- Upgraded key-value pair (KVP) detection model
Form parser v2.1 (pretrained-form-parser-v2.1-2023-06-26) is in Public Preview, which uses our native PDF text extraction model on PDF documents.
The Form Parser features has the following limitations:
- Checkbox doesn't support radio buttons and might not reliably parse all selection marks or keyless checkboxes.
- If there is a key without a value, the model might not parse it.
- The key-value pair parsing on non-latin languages might not be as high of quality as latin languages.
- For tables, only simple tables are supported (no support for merged cells).
Connectivity Tests now includes a feature that verifies connectivity from a VM to a Private Service Connect endpoint. For more information, see Create and run Connectivity Tests.
Connectivity Tests now includes a feature that verifies connectivity from a VM or an IP address to a load balancer. For more information, see Create and run Connectivity Tests.
Payload unwrapping for push subscriptions is now available. Payload unwrapping lets you deliver Pub/Sub messages stripped of all message metadata, except for the message data. With payload unwrapping enabled, message data is delivered directly as the HTTP body.
General availability support for the following integration:
Model tuning updates for text-bison:
- Upgraded tuning pipeline now offers more efficient tuning and better performance on text-bison.
- New
learning_rateparameter lets you adjust the step size at each iteration.
For details, see Tune language foundation models.
All service attachments, including those created before March 1, 2023, consume one NAT IP address for each connected endpoint or backend. For more information, see NAT subnet sizing.
July 17, 2023
BatchDocumentation has been added for Cloud Life Sciences users to explain how to migrate to Batch. For more information, see Migrate to Batch from Cloud Life Sciences.
Primary and foreign key table constraints are now generally available. In addition to the features available in preview, you can now also manage constraints through the BigQuery API and view constraints in the BigQuery console.
A weekly digest of client library updates from across the Cloud SDK.
The google.cloud.bigquery.storage.v1beta2 API package for BigQueryWrite operations is deprecated and will be removed on July 17, 2024. After that date, requests to that package version for use with the BigQuery Storage Write API will fail. Data written to BigQuery using the BigQuery Storage Write API is accessible by using the google.cloud.bigquery.storage.v1 package.
Next steps: If you call the API directly, switch to google.cloud.bigquery.storage.v1, the generally available (GA) version of the API, to prevent any impact on your workflow.
On July 17, 2023 we released the preview version of Blockchain Analytics.
Blockchain Analytics offers indexed blockchain data made available through BigQuery for easy analysis through SQL. Starting with Ethereum, Blockchain Analytics offers you access to reliable data without the overhead of operating nodes or developing and maintaining an indexer.
Documentation: What is Blockchain Analytics?
In the SAP Ariba plugin 1.2.1, a Token Endpoint field that takes an authentication URL has been added to the plugin properties. The plugin is available in Cloud Data Fusion version 6.7 and later.
In Cloud Data Fusion versions 6.7 and later, SAP Ariba plugin version 1.2.1 fixes the issue causing the following error after entering authentication credentials: CDF_ARIBA_01501 - Failed to call given Ariba service. This issue occurs when the SAP Ariba sandbox exists in the following locations:
- US
- EU
- UAE
- KSA
Cloud Life Sciences is deprecated. New projects cannot onboard to Cloud Life Sciences, and the service will no longer be available on Google Cloud after July 8, 2025. Use cases for Cloud Life Sciences are now supported by Batch. To learn how to migrate your workload, see Migrate to Batch.
A weekly digest of client library updates from across the Cloud SDK.
You can now create synthetic monitors, which let you continuously test the availability, consistency, and performance of your services and application web pages and APIs, by using automated script based tests. Synthetic monitors periodically probe the endpoints of your application and they record whether or not a probe was successful, along with additional data about the request. For more information, see Synthetic monitoring overview.
You can now enable query insights for multiple instances at a time.
Beginning October 16, 2023, the Autoclass feature will change its storage class transition behavior.
By default, new buckets with Autoclass enabled will only transition objects between the Standard and Nearline storage classes.
However, you can continue to create buckets that transition objects between all storage classes by choosing to opt-in.
Beginning October 16, 2023, the Autoclass feature and the matchesStorageClass condition for Object Lifecycle Management will be incompatible.
- You will not be able to modify any other bucket metadata for affected buckets until either the
matchesStorageClasscondition is removed or the Autoclass feature is disabled.
Beginning October 16, 2023, the following pricing changes apply to buckets that use the Autoclass feature:
Each storage class transition from Coldline or Archive storage to Standard storage will change from being free to being charged as a Class A operation at the Standard storage rate.
Each Class B operation, such as reading object data, will change from being charged at the rate of the object's storage class at the time of the operation to being charged at the Standard storage rate.
After October 30, 2023, billing for objects in Autoclass buckets will use Autoclass-specific SKUs.
Config Controller now uses the following versions of its included products:
- Config Connector v1.106.0, release notes
- Anthos Config Management v1.15.2, release notes
The Custom Document Splitter (CDS) within Document AI Workbench is now Generally Available (GA) for production use cases to split and classify multiple documents within a single file. With this release, all Workbench processors currently offered (Custom Document Extractor, Custom Document Classifier, and Custom Document Splitter) are available in GA.
Launched the following features for CDS:
- CDS now supports up to 1,000-page documents for async/batch prediction and up to 200-page documents when importing, labeling, training, or evaluating.
- CDS model evaluation for document split and classification
- Prepare a CDS training dataset faster by bulk labeling documents at import across multiple folders.
Released the the following enhancements for CDS:
- Improved labeling and evaluation experience with the ability to review overall document splits and classifications while viewing individual pages in a side-by-side view.
- Document names are now used in error messaging to improve troubleshooting.
- Hyphens are allowed in schema names.
A weekly digest of client library updates from across the Cloud SDK.
Cloud Armor supports parsing of the GraphQL content-type in public preview. For more information, see POST body content parsing.
Cloud Armor allows you to filter using custom rules or apply Adaptive Protection based on originating client IP addresses in public preview. If you have an upstream proxy, you can use this feature to evaluate Cloud Armor rules against the original clients' IP addresses, rather than your upstream proxy's IP address. For more information, see the rules language reference.
Cloud Deploy now provides the ability to pass deploy parameters to your manifests, per delivery pipeline, per target, and per release (in preview).
Redis version 7.0 is now Generally Available for Memorystore for Redis.
A weekly digest of client library updates from across the Cloud SDK.
Python
Changes for google-cloud-pubsub
2.18.0 (2023-07-12)
Features
Bug Fixes
Documentation
Google Cloud's Agent for SAP version 2.1
Version 2.1 of Google Cloud's Agent for SAP is generally available (GA). This version introduces the SAP system discovery and support bundle collection features, and includes bug fixes.
For more information, see What's new with Google Cloud's Agent for SAP.
Imagen on Vertex AI now offers the following Generally Available (GA) features:
- Image generation (text-to-image generation)*
- Image editing*
- Image visual captioning
- Visual Question Answering (VQA)
* Restricted access feature.
For more information about Imagen or how to get access to restricted GA or Preview features, see the Imagen on Vertex AI overview.
Imagen now supports human face generation for the following features:
* Restricted access feature.
Human face generation is enabled by default, except for images with children and/or celebrities. For more information, see the usage guidelines.
The Vertex AI PaLM API has added support for the following languages:
- Spanish (es)
- Korean (ko)
- Hindi (hi)
- Chinese (zh)
For the complete list of supported languages, see Supported languages.
You can publish a service that is hosted on an internal passthrough Network Load Balancer that forwards traffic on all ports (--ports=all). This feature is available in General Availability.
July 14, 2023
Access ApprovalAccess Approval supports Cloud Tasks in the Preview stage.
To create a client network, the Google Cloud console intake form now accepts VLAN attachment names and project number instead of pairing keys if your VLAN attachments are in a different project.
Projects enrolled in the Security Command Center Premium tier now have access to SQL-like asset queries for that project. Previously asset queries were only available when an organization was enrolled in the Security Command Center Premium tier.
The PORTUGAL_SOCIAL_SECURITY_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
New Dataproc Serverless for Spark runtime versions:
- 1.1.23
- 2.0.31
- 2.1.10
Clusters that use a driver node group now configure YARN queues with user-limit-factor set to 2, allowing for a single user to burst to 2x utilization of capacity, which is set to 50. This achieves better resource utilization for workloads submitted by a single user.
Upgraded the Cloud Storage connector version to 2.2.16 in Dataproc Serverless for Spark runtimes.
Support for Firestore point-in-time recovery (PITR) feature that provides protection against accidental deletion or writes is now available in Preview.
Support for Firestore in Datastore mode point-in-time recovery (PITR) feature that provides protection against accidental deletion or writes is now available in Preview.
New Autopilot clusters created with version 1.27.3-gke.100 or later are now provisioned with e2-small default nodes, which are removed immediately after cluster creation. With this change, DaemonSets are guaranteed to schedule on all candidate nodes, as long as you follow best practices for DaemonSets on Autopilot.
Google Cloud's Agent for SAP is packaged with "for SAP" OS images
Google Cloud's Agent for SAP is packaged with the following "for SAP" OS images provided by Google Cloud:
- RHEL: all "for SAP" images
- SLES: SLES 15 SP4 for SAP and later versions
For information about the operating systems supported by Google Cloud's Agent for SAP, see Supported operating systems.
Read Envoy Security Bulletin CVE-2023-35945 about Envoy security vulnerabilities and update Envoy proxies in your Traffic Director installation to Envoy release 1.24.9, 1.25.8 or 1.26.3.
July 13, 2023
Anthos clusters on AWSYou can now launch clusters with the following Kubernetes versions:
- 1.24.14-gke.1400
- 1.25.10-gke.1200
- 1.26.5-gke.1200
1.24, 1.25, 1.26
Configured the cluster autoscaler to balance the number of nodes across availability zones using the parameter --balance-similar-node-groups.
1.25
Migrated node pool metrics agent and metrics server to authenticated kubelet port.
1.26
Fixed an issue where Kubernetes 1.26.2 incorrectly applied the default StorageClass to PersistentVolumeClaims with the deprecated annotation volume.beta.kubernetes.io/storage-class. (This issue is also fixed in release 1.15.1.)
This release fixes the following vulnerabilities:
Applications may experience timeouts due to netfilter connection tracking (conntrack) table insertion failures. Insertion failures can occur even when the conntrack table has room for new entries. The failures are caused by changes in kernel 5.15 and higher that restrict table insertions based on chain length.
You can now launch clusters with the following Kubernetes versions:
- 1.24.14-gke.1400
- 1.25.10-gke.1200
- 1.26.5-gke.1200
1.25
Migrated node pool metrics agent and metrics server to authenticated kubelet port.
1.26
Fixed an issue where Kubernetes 1.26.2 incorrectly applied the default StorageClass to PersistentVolumeClaims with the deprecated annotation volume.beta.kubernetes.io/storage-class. (This issue is also fixed in release 1.15.1.)
This release fixes the following vulnerabilities:
Applications may experience timeouts due to netfilter connection tracking (conntrack) table insertion failures. Insertion failures can occur even when the conntrack table has room for new entries. The failures are caused by changes in kernel 5.15 and higher that restrict table insertions based on chain length.
hybrid v1.10.1
On July 13, 2023 we released an updated version of the Apigee hybrid software, v1.10.1.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.10.1.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 289254725 | Implemented a fix to prevent failure of proxy deployments that include the OASValidation policy. |
| Bug ID | Description |
|---|---|
| 281561243 | Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerability: |
| 290067464 | Security fixes for apigee-stackdriver-logging-agent. This addresses the following vulnerability: |
| 290068742 | Security fixes for apigee-udca. This addresses the following vulnerability: |
| 290065830 | Security fixes for apigee-udca. This addresses the following vulnerability: |
The SAP OData plugin (version 0.9.1) is available in the Cloud Data Fusion SAP Hub (all versions) with the following changes:
- Fixed an issue in the SAP OData batch source causing you not to receive a valid error message if the base URL provided is invalid.
- A warning has been added to the log message when you provide a batch size that is larger than the maximum allowed batch size.
Dedicated Cloud Interconnect support is available in the following colocation facility:
- CS LoxInfo Data Center - The Cloud, Bangkok
For more information, see the Locations table.
cos-101-17162-210-54
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Fixed CVE-2023-24329 in python.
Fixed CVE-2021-3737 in python.
Fixed CVE-2022-0391 in python.
Fixed CVE-2021-4189 in python.
Fixed CVE-2021-3426 in python.
Fixed CVE-2021-23336 in python.
Fixed CVE-2021-3733 in python.
Fixed CVE-2023-31486 in perl.
Fixed CVE-2023-3090 in the Linux kernel.
cos-dev-109-17749-0-0
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.1.38 | v23.0.3 | v1.7.2 | v470.182.03(default),v525.105.17 |
Updated google-guest-agent to v20230628.00.
Updated the Linux kernel to v6.1.38.
Upgraded localtoast from v1.1.5.1 to v1.1.6.
cos-105-17412-101-51
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.109 | v23.0.3 | v1.7.0 | v470.182.03(default),v525.105.17 |
Fixed CVE-2023-3390 in the Linux kernel.
Fixed CVE-2023-3090 in the Linux kernel.
cos-93-16623-402-43
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Fixed CVE-2023-31486 in perl.
Fixed CVE-2023-3090 in the Linux kernel.
cos-97-16919-294-51
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.176 | v20.10.14 | v1.6.20 | v470.182.03(default),v525.105.17 |
Fixed CVE-2023-31486 in perl.
Fixed CVE-2023-3090 in the Linux kernel.
Enable GenAI search (private preview) to support large documents up to 25K words.
The managed Cloud Storage FUSE CSI driver for GKE is now GA in versions 1.26.5 and later. You can use this driver to consume Cloud Storage buckets for GKE workloads.
Pro feature: Scheduled delivery using Chat
Looker Studio Pro users can schedule reports to be delivered using Google Chat. You can send reports to individual recipients or to entire Chat spaces.
Pro feature: Filter by email address for scheduled reports
Looker Studio Pro users can add row-level security to the data in a report scheduled to be delivered through email.
Learn more about Chat delivery and filter by email address.
See report and data source location on the home page
The Location field on the Looker Studio home page shows where your Looker Studio assets live. For free Looker Studio users, you can see if a report or data source is owned by you or has been shared with you. For Looker Studio Pro users, you'll see whether the asset lives in your My Workspace, lives in a Team Workspace, or has been shared with you directly.
Recommendations from the IAM recommender are now available as findings in Security Command Center in a Preview release.
The following IAM recommender recommendations are now published as Vulnerability class findings in Security Command Center:
- IAM role has excessive permissions
- Service agent role replaced with basic role
- Service agent granted basic role
- Unused IAM role
For more information, see Security sources > IAM recommender.
Support for batch text (text-bison) requests
is now available in (GA).
You can review pricing for the chat-bison model at
Vertex AI pricing page.
July 12, 2023
Anthos Attached ClustersAdded support for managing Anthos attached clusters in the Google Cloud console. You can now use a user-friendly graphical interface to manage your Amazon Elastic Kubernetes Service (EKS) and Azure Kubernetes Service (AKS) clusters on the Anthos platform. Using the Google Cloud console, you can view cluster status, update attached cluster components, and detach clusters.
For more information, including instructions, see the following documentation:
On July 12, 2023, we released an updated version of Apigee X.
Preview release of non-VPC peering option for Apigee provisioning Apigee now supports a provisioning option that does not require VPC peering. With this approach, you are not required to provide networks and IP ranges during the Apigee provisioning process. Instead, you use Private Service Connect (PSC) for routing northbound traffic to Apigee and southbound traffic to target services running in your Google Cloud projects.
Non-VPC peering is supported for command-line (CLI) provisioning steps only. You can perform non-VPC provisioning for subscription, Pay-as-you-go, and evaluation installations of Apigee.
To learn more, see Apigee networking options.
The following BigQuery ML feature preprocessing functionality is now generally available (GA).
You can export models that use the TRANSFORM clause for feature preprocessing to the TensorFlow SavedModel format. There are 13 data types supported for TRANSFORM clause input, and 127 SQL functions supported for use within the TRANSFORM clause.
You can also now deploy a model trained with the TRANSFORM clause to Vertex AI and locally.
Use the following functions to perform feature preprocessing:
Custom holiday modeling for time series forecasting is now in preview. This release offers the following features to improve the transparency, flexibility, and explainability of time series forecasting in BigQuery ML:
- New CREATE MODEL syntax to specify custom holiday modeling for time series models.
- The new ML.HOLIDAY_INFO function, which returns the list of holidays being modeled by an ARIMA_PLUS or ARIMA_PLUS_XREG time series forecasting model.
- An updated ML.EXPLAIN_FORECAST function, which includes an explanation of the holiday effect for each holiday included in the model.
A new public table, bigquery-public-data.ml_datasets.holidays_and_events_for_forecasting, has also been added to provide easy look-up of the built-in holidays used in time series forecasting models.
Try these features with the Use custom holidays in a time-series forecasting model tutorial.
The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.
- Absolute Mobile Device Management (
ABSOLUTE) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - BIND (
BIND_DNS) - Check Point (
CHECKPOINT_FIREWALL) - Chrome Management (
N/A) - Cisco Meraki (
CISCO_MERAKI) - Cloud Audit Logs (
N/A) - Cloud Load Balancing (
GCP_LOADBALANCING) - Cloudflare Audit (
CLOUDFLARE_AUDIT) - F5 ASM (
F5_ASM) - Fortinet FortiEDR (
FORTINET_FORTIEDR) - IBM Security Verify SaaS (
IBM_SECURITY_VERIFY_SAAS) - IBM Security Verify SaaS (
IBM_SECURITY_VERIFY_SAAS) - Imperva FlexProtect (
IMPERVA_FLEXPROTECT) - Jamf Protect Telemetry (
JAMF_TELEMETRY) - Juniper Software Defined Wide Area Network (
JUNIPER_SDWAN) - Microsoft AD (
WINDOWS_AD) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS) - Microsoft CASB (
MICROSOFT_CASB) - Microsoft Powershell (
POWERSHELL) - Microsoft SQL Server (
MICROSOFT_SQL) - MISP Threat Intelligence (
MISP_IOC) - Netskope (
NETSKOPE_ALERT) - Okta (
OKTA) - SecureAuth (
SECUREAUTH_SSO) - Security Command Center Threat (
N/A) - SentinelOne EDR (
SENTINEL_EDR) - Sierra Wireless (
SIERRA_WIRELESS) - Sourcefire (
SOURCEFIRE_IDS) - Stormshield Firewall (
STORMSHIELD_FIREWALL) - Versa Firewall (
VERSA_FIREWALL) - Windows Event (
WINEVTLOG) - Workspace Activities (
WORKSPACE_ACTIVITY)
For details about changes in each parser, see Supported default parsers.
Chronicle Curated Detections has been enhanced with new detection content for Linux threats. These new rule sets help identify threats in Linux environments using AuditD and Unix System logs.
Release Notes 6.2.30: Playbooks not always saved correctly within Platform (ID #00243484)
Airflow 2.5.3 is available in Cloud Composer images.
Fixed the retrying of transient errors in Composer Agent when creating Cloud Composer 2 environments.
(Available without upgrading) The default amount of memory available to the web server, schedulers, and workers is changed from 3.75 GB per CPU core to 4 GB per CPU core. This value is used only if you do not specify the amount of memory available to these environment components.
(Available without upgrading) Improved the performance of DAG UI in Private IP environments.
Cloud Composer 2.3.4 images are available:
- composer-2.3.4-airflow-2.5.3
- composer-2.3.4-airflow-2.5.1 (default)
- composer-2.3.4-airflow-2.4.3
Cloud Composer versions 2.0.20 and 1.19.3 have reached their end of full support period.
Cloud SQL now offers two editions of Cloud SQL to support your various business and application needs: Cloud SQL Enterprise Plus edition and Cloud SQL Enterprise edition. Each edition provides different performance and availability characteristics to meet the needs of your applications.
Cloud SQL Editions are only available for Cloud SQL for MySQL and Cloud SQL for PostgreSQL.
For more information about Cloud SQL editions, see Introduction to Cloud SQL editions.
Cloud SQL now offers two editions of Cloud SQL to support your various business and application needs: Cloud SQL Enterprise Plus edition and Cloud SQL Enterprise edition. Each edition provides different performance and availability characteristics to meet the needs of your applications.
Cloud SQL Editions are only available for Cloud SQL for MySQL and Cloud SQL for PostgreSQL.
For more information about Cloud SQL editions, see Introduction to Cloud SQL editions.
Generally available: You can enable faster network packet processing by using the Data Plane Development Kit (DPDK). DPDK helps you to optimize VMs that run network-intensive workloads, such as video streaming or voice calls.
Cloud Deploy now supports Skaffold version 2.6. The default Skaffold version remains 2.3.
GKE Dataplane V2 observability is now available in Public Preview starting in GKE versions 1.26.4-gke.500 or later, or 1.27.1-gke.400 or later. You can now enable Dataplane V2 metrics and observability tools on your cluster. Dataplane V2 metrics are included in new Autopilot clusters and opt-in for new Standard clusters. You can opt-in to enable Dataplane V2 observability tools for Autopilot and Standard clusters. Existing clusters can also be updated to enable metrics and observability tooling.
For more information, check out GKE Dataplane V2 observability.
In GKE version 1.24 and later, new beta APIs are, by default, disabled in new clusters. Starting in version 1.27, which is the first new minor version since 1.24 where new beta APIs are introduced, you can enable new APIs on cluster creation or for an existing cluster.
For more information, see how to Use Kubernetes beta APIs with GKE clusters.
Revision for the release note announced on June 26, 2023
Starting August 2023, Cloud DNS will become the default DNS provider for new GKE Autopilot clusters created with version 1.25.9-gke.400 or later, or version 1.26.4-gke.500 or later (effectively replacing kube-dns). The rollout will be gradual and expected to be completed by August 11, 2023. To learn more, see Cloud DNS for GKE.
Looker 23.12 includes the following changes, features, and fixes.
Expected Looker (original) rollout start: Tuesday July 18, 2023
Expected Looker (original) final deployment and download available: Thursday July 27, 2023
Expected Looker (Google Cloud core) deployment start: Monday July 31, 2023
Expected Looker (Google Cloud core) deployment end: Friday August 11, 2023
The Looker API reference documentation is now available on the Looker documentation site at https://cloud.google.com/looker/docs/reference/looker-api/latest.
Two new "cookbooks," or collections of instructions for common use cases, have been added to the Best Practices section of the Looker documentation site. The Getting the most out of Looker visualizations guide describes some common use cases for customizing visualizations, and the Maximizing code reusability with DRY LookML guide presents a series of use cases for applying DRY (don't repeat yourself) principles to your LookML development.
Changes to the settings API: Users with the manage_embed_settings or manage_privatelabel permission will now have limited access to the API. Users with the manage_embed_settings permission can update the embed_cookieless_v2 field, and users with the manage_privatelabel permission can update the whitelabel_configuration field.
For customer-hosted Looker instances, Looker now fails to start if an appropriate version of the git command line tool is unavailable.
The new Border Radius option for custom embed themes lets you adjust how rounded the corners in dashboard tiles will appear.
The Lexp expression matches_filter now supports the tier, location, and zip code LookML field types.
BigQuery OAuth access for a user's Drive is now read-only.
Looker (Google Cloud core) now supports the following regions:
- us-east1 (South Carolina)
- europe-north1 (Finland)
- europe-west1 (Belgium)
In Looker 23.12, Looker rendering supports Chrome versions up to and including Chrome 114. Looker versions earlier than Looker 23.10 support up to Chrome version 109.
The documentation has been updated regarding the behavior of the order_by_fields parameter when a table is being downloaded.
Incorrect alignment of error messages on dashboard visualizations has been fixed.
Previously, a derived table could fail to pick up on a filter value declared on the Explore level in a view that referenced the derived table via ${SQL_TABLE_NAME}. This issue has been fixed.
Previously, a query that used custom measures could fail to render data on dialects that support APPROXIMATE COUNT DISTINCT. This issue has been fixed.
LookML that is generated from results will no longer double-quote labels that contain spaces.
Looker access filters now work with bind-filters and bind_all_filters when used in an NDT.
Looker Marketplace functionality has been restored for Looker (Google Cloud core).
Failures during updates to Marketplace installations now show meaningful errors.
Connecting VPC networks by using Network Connectivity Center is now available in Preview.
This feature lets you connect two or more VPC networks, represented as spokes, to a hub in the same or a different project for full mesh connectivity.
The Quota page displays only the default quota limits and doesn't include any additional quotas provided by Google.
For information about VPC Service Controls quotas, see Quotas and limits.
July 11, 2023
Artifact RegistryCleanup policies for Artifact Registry are now in Preview. Cleanup policies help you manage artifacts by automatically deleting artifacts that you no longer need, while keeping artifacts that you want to store.
Deletions requested by Cleanup policies count against Artifact Registry delete request quota and limits.
Starting July 11, 2023, Artifact Registry write requests and delete requests have their own quotas. For more information on this change, see Quotas and limits.
When you create your first BackupPlan or RestorePlan resource for a cluster, the Backup for GKE agent is automatically installed in that cluster.
Backup for GKE agent now supports a blocklist for restoring cluster-scoped and namespaced resources. For more information, see the detail.
Global external Application Load Balancers now support Shared VPC configurations where the load balancer's forwarding rule, target proxy, and URL map, can be created in a host or service project, while the backend services and backends can be distributed across multiple service projects in the Shared VPC environment. This is referred to as cross-project service referencing.
Cross-project service referencing gives service developers and admins autonomy over the exposure of their services through the centrally managed load balancer.
For details, see:
This feature is available in Preview.
Cloud SQL now supports cancelling the import and export of data into Cloud SQL for MySQL instances.
MySQL 5.7.40 has been upgraded to 5.7.42. For more information, see MySQL 5.7 release notes.
Cloud SQL now supports cancelling the import and export of data into Cloud SQL for PostgreSQL instances.
Config Connector version 1.106.0 is now available.
Added support for customization on cnrm-webhook-manager pods resource requests/limits.
Added support for RunJob resource.
Optimized HPA rule for cnrm-webhook-manager with new memory targetAverageUtilization.
Added support for KMS key deletion when being orphaned.
Disabled abandon-on-uninstall webhook.
Resource VPCAccessConnector(v1beta1):
- Added
status.selfLinkfield.
Resource ComputeDisk(v1beta1):
- Added
spec.guestOsFeaturesfield. - Added
spec.licensesfield.
Resource ComputeImage(v1beta1):
- Added
spec.storageLocationsfield.
Resource DataflowFlexTemplateJob(v1beta1):
- Added
status.typefield.
Resource DatastreamStream(v1alpha1):
- Added
spec.sourceConfig.mysqlSourceConfig.maxConcurrentBackfillTasksfield.
Resource GKEHubFeature(v1beta1):
- Added
spec.spec.fleetobservabilityfield.
Resource MonitoringAlertPolicy(v1beta1):
- Added
spec.alertStrategy.notificationChannelStrategyfield. - Added
spec.conditions.items.conditionThreshold.forecastOptionsfield.
Resource SQLInstance(v1beta1):
- Added
spec.settings.advancedMachineFeaturesfield.
Resource StorageTransferJob(v1beta1):
- Added
spec.transferSpec.awsS3DataSource.pathfield.
Dialogflow CX now supports speech recognition model selection.
Support for the northamerica-northeast2 (Toronto) region.
Support for the northamerica-northeast2 (Toronto) region.
You can now troubleshoot common GKE issues by using the new "interactive playbook" dashboards in Cloud Monitoring: unschedulable pods and crashlooping containers. You can also access the interactive playbooks from GKE UI insights and set alerts that will allow you to know once those issues occurs.
For information about using these dashboards, see the GKE troubleshooting documentation for unschedulable pods and crashlooping.
Starting in GKE version 1.27, cluster autoscaler always considers Compute Engine Reservations when making the scale-up decisions. The node pools with matching unused reservations are prioritized when choosing the node pool to scale up, even when the node pool is not the most efficient one. Additionally, unused reservations are always prioritized when balancing multi-zonal scale-ups.
For more information, see how to use cluster autoscaler.
Workforce identity federation now supports browser-based sign-in with the Google Cloud CLI. The feature is generally available (GA). To use it, see Browser-based sign-in in Obtain short-lived tokens for workforce identity federation, or locate the Browser-based sign-in section in the configuration guide for your identity provider.
Preview: Guided Deployment Automation in Workload Manager for SAP
The preview release of the Guided Deployment Automation tool in Workload Manager is available. You can use this tool to configure and deploy SAP systems on Google Cloud.
The preview release includes initial support for the deployment of SAP S/4HANA in the distributed and distributed with high availability (HA) architectures.
For more information, see About Guided Deployment Automation.
Preview: Workload Manager now supports deploying SAP workloads on Google Cloud. You can configure and deploy a SAP S/4HANA system using the Guided Deployment Automation tool in Workload Manager. For more information, see About Guided Deployment Automation.
July 10, 2023
Anthos clusters on VMwareAnthos clusters on VMware 1.15.2-gke.44 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware. 1.15.2-gke.44 runs on Kubernetes 1.26.2-gke.1001.
The following issues are fixed in 1.15.2-gke.44:
- Fixed a bug where after an upgrade to 1.15, clusters used the non-high-availability (HA) Connect Agent.
- Fixed a
known issue
where
$in the private registry username caused admin control plane machine startup failure. - Fixed a known issue where user cluster update failed after KSA signing key rotation.
- Fixed a
known issue
where
gkectl diagnose snapshotfailed to limit the time window forjournalctlcommands running on the cluster nodes when you take a cluster snapshot with the--log-sinceflag.
The following vulnerabilities are fixed in 1.15.2-gke.44:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
On July 10, 2023, we released an updated version of Apigee X (1-10-0-apigee-5).
| Bug ID | Description |
|---|---|
| 289254725 | Implemented fix to prevent failure of proxy deployments that include the OASValidation policy. |
| N/A | Upgraded infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 273693152 | Fixed SAMLAssertion policy parsing to limit the number of entities that will be parsed to 10000. Any attempt to parse more than 10000 entities will generate an error. |
| 273695718 | Fixed DataCapture policy to avoid evaluation of external entities during XML parsing for variable collection. |
| 273929507 | Fixed issue with potential Java security bypass in LookupCache policy. Certain objects which implement |
| 273950705 | Fixed issue in PythonScript policy to prevent execution of arbitrary Java code. With this fix, the runtime does not allow execution of python code added to a |
PHP 7.4, 8.1, and 8.2 are now generally available. These versions require you to specify an operating system version in your app.yaml file. Learn more.
The following compliance programs now support the list of products below:
- Australia Regions with Assured Support
- Canada Regions and Support
- Canada Protected B
- Israel Regions and Support
- US Regions and Support
The following products are now supported. See supported products for more information:
- Cloud Data Loss Prevention
- Certificate Authority Service
- Cloud Composer
Backup and DR Service 11.0.5.447 is now available to update your appliance. Refer to the instructions to update your appliance.
Backup and DR Service is now integrated with cloud Identity and Access Management (IAM). Refer to IAM roles and permissions to learn more.
Backup and DR Service is now integrated with cloud audit logging.
Backup and DR service now manages hotfixes on backup/recovery appliances.
Backup and DR Service significantly reduced recovery time objective (RTO) for Oracle databases by bringing up production workloads almost instantly, running from backup storage, and then migrating the database to production storage online—while applications are up and running.
Chronicle provides multiple methods to define how data in original raw logs are parsed and normalized to a Unified Data Model (UDM) record. Using the Self Service Parser Management feature, customers can now create and customize parsers. For more information, see Overview of log parsing and Manage prebuilt and custom parsers.
Committed use discounts are now generally available (GA) for Cloud Bigtable in exchange for a commitment to continuously spend a certain amount on Bigtable nodes for one year or three years. For details, see Committed use discounts.
Time ranges are now synchronized between select Logging and Monitoring pages.
Cloud TPU now supports TensorFlow 2.13.0. For more information see the TensorFlow 2.13.0 Release Notes.
Preview: You can use instant snapshots to take in-place disk backups that can be restored to new disks under a minute.
Instant snapshots are ideal for rapid data restoration within the same location as the source disk. For more information, see Instant snapshots.
A weekly digest of client library updates from across the Cloud SDK.
Python
Changes for google-cloud-dataflow-client
0.8.4 (2023-07-04)
Bug Fixes
New Dataproc on Compute Engine image versions:
- 2.0.69-debian10, 2.0.69-rocky8, 2.0.69-ubuntu18
- 2.1.17-debian11, 2.1.17-rocky8, 2.1.17-ubuntu20
Upgraded the Cloud Storage connector version to 2.2.16 for Dataproc on Compute Engine 2.0 and 2.1 images.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for datastore/admin/apiv1
1.12.1 (2023-07-07)
Bug Fixes
Python
Changes for google-cloud-datastore
2.16.1 (2023-07-05)
Bug Fixes
Enterprise Search: Snippets no longer provide page numbers
Snippets are returned as brief extracts of text of uniform length. They no longer provide page numbers. If you previously used snippets as inputs for large language models to generate responses and summaries, we recommend using extractive answers or extractive segments. If you need page numbers in your extracts, we recommend using extractive answers, which provide page numbers where available.
Enterprise Search: Snippets with hit highlighting
Snippets in search responses are available with hit highlighting for rendering in UIs.
For more information, see Use snippets and extracted content.
Enterprise Search: Languages
Search and snippets results are supported in English (en-US), Spanish (es-ES), German (de-DE), and Italian (it-IT).
For more information, see Languages.
The new release of the GKE Gateway controller (2023-R2) is now generally available. With this release, the GKE Gateway controller will provide the following new capabilities:
- New GatewayClasses supporting the regional external Application Load Balancer
- Identity-aware Proxy (IAP) Integration
- Custom request and response headers
- URL Rewrites and Path Redirects
To learn more, see the supported capabilities per GatewayClass.
Content encryption (DRM) is now supported.
Job processing optimizations can now be disabled.
You can now set the priority of individual jobs in batch mode.
Support for PaLM 2 for Chat (chat-bison)
is now available in (GA).
You can review pricing for the chat-bison model at
Vertex AI pricing page.
By default, public advertised prefixes can be used only to create regional public delegated prefixes. If you need to create global public delegated prefixes, you must request access. For more information about this behavior change and how to request access, see Behavior changes for BYOIP.
July 08, 2023
BatchDocumentation has been added to explain how to apply labels to a Batch job and its resources. Labels are key-value pairs that can be used to group and organize Batch and Compute Engine resources. For more information, see Organize resources using labels.
July 07, 2023
Apigee Adapter for Envoyv2.1.1
On June 7, 2023, we released version 2.1.1 of Apigee Adapter for Envoy.
An issue was fixed where quotas were being improperly duplicated between operations instead of being shared at the Product level.
Batch is available in the following regions:
asia-northeast2(Osaka)asia-northeast3(Seoul)australia-southeast1(Sydney)europe-west1(Belgium)europe-west9(Paris)
For more information, see Locations.
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- Cloud Spanner
spanner.googleapis.com/InstanceConfig
You can now troubleshoot common GKE issues like unschedulable pods and crashlooping containers by using the new "interactive playbook" dashboards in Cloud Monitoring. For information about using these dashboards, see the GKE troubleshooting documentation for unschedulable pods and crashlooping.
Cloud SQL for MySQL now supports up to 500,000 tables for instances that meet the minimum hardware requirements of 32+ cores and 200G+ memory. For more information, see table limit.
Custom audit logging for Cloud Storage is now generally available (GA). In addition to using the Cloud Storage JSON API, you can now attach custom information to audit logs for requests by using the following tools:
- The gcloud or gsutil command-line tools
- The Cloud Storage client libraries
- The Cloud Storage XML API
- Signed URLs
Dataproc Serverless Spark 1.1 and 2.0 runtime subminor versions can now be used 365 days after their release (instead of 90 days).
The goog-dataproc-batch-id, goog-dataproc-batch-uuid and goog-dataproc-location labels are now automatically applied to Dataproc Serverless batch resources.
Dataproc Serverless for Spark now supports updating the BigQuery connector using the dataproc.sparkBqConnector.version and dataproc.sparkBqConnector.uri properties
see Use the BigQuery connector with Dataproc Serverless for Spark.
Multiple databases now available in Preview.
Multiple databases now available in Preview.
(2023-R15) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.22.17-gke.8000
- 1.22.17-gke.11400
- 1.23.17-gke.5600
- 1.24.12-gke.500
- 1.24.12-gke.1000
- 1.24.13-gke.500
- 1.26.3-gke.1000
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.13-gke.2500 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
Stable channel
- Version 1.26.5-gke.1200 is now the default version in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.23.17-gke.5600
- 1.24.12-gke.1000
- 1.25.8-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.25 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
Regular channel
The following versions are now available in the Regular channel:
The following versions are no longer available in the Regular channel:
- 1.23.17-gke.6800
- 1.24.13-gke.2500
- 1.25.9-gke.2300
- 1.26.3-gke.1000
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.7000 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.10-gke.1200 with this release.
Rapid channel
- Version 1.27.2-gke.2100 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.12700
- 1.23.17-gke.7000
- 1.24.14-gke.2100
- 1.25.10-gke.1400
- 1.26.5-gke.1400
- 1.27.2-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.14100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.7700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.27 to version 1.27.2-gke.2100 with this release.
(2023-R15) Version updates
- Version 1.27.2-gke.2100 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.12700
- 1.23.17-gke.7000
- 1.24.14-gke.2100
- 1.25.10-gke.1400
- 1.26.5-gke.1400
- 1.27.2-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.14100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.7700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.2700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.27 to version 1.27.2-gke.2100 with this release.
(2023-R15) Version updates
The following versions are now available in the Regular channel:
The following versions are no longer available in the Regular channel:
- 1.23.17-gke.6800
- 1.24.13-gke.2500
- 1.25.9-gke.2300
- 1.26.3-gke.1000
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.7000 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.10-gke.1200 with this release.
(2023-R15) Version updates
- Version 1.26.5-gke.1200 is now the default version in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.23.17-gke.5600
- 1.24.12-gke.1000
- 1.25.8-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.25 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
(2023-R15) Version updates
The following control plane and node versions are now available:
The following control plane versions are no longer available:
- 1.22.17-gke.8000
- 1.22.17-gke.11400
- 1.23.17-gke.5600
- 1.24.12-gke.500
- 1.24.12-gke.1000
- 1.24.13-gke.500
- 1.26.3-gke.1000
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.13-gke.2500 with this release.
Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
July 06, 2023
Anthos clusters on VMwareAnthos clusters on VMware 1.14.6-gke.23 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.6-gke.23 runs on Kubernetes 1.25.10-gke.1200.
The following issues are fixed in 1.14.6-gke.23:
- Fixed a
known issue
where
$in the private registry username caused admin control plane machine startup failure. - Fixed a
known issue
where
gkectl diagnose snapshotfailed to limit the time window forjournalctlcommands running on the cluster nodes when you take a cluster snapshot with the--log-sinceflag. - Fixed a known issue where user cluster update failed after KSA signing key rotation.
The following vulnerabilities are fixed in 1.14.6-gke.23:
High-severity container vulnerabilities:
On July 6, 2023, we released an updated version of Apigee X.
Preview release of Pay-as-you-go pricing with updated attributes
Apigee is updating its Pay-as-you-go pricing model, making it possible to start using Apigee at a significantly reduced initial cost and right-size ongoing expenses to match precise usage.
To learn how to get started with the updated Pay-as-you-go pricing experience, see Pay-as-you-go (updated attributes) pricing overview.
Preview release of new environment types
Apigee announces the Preview release of three distinct environment types: Base, Intermediate, and Comprehensive. Each environment type offers varying degrees of capabilities and costs; you can tailor pricing to suit your needs.
For more information, see Apigee Pay-as-you-go environment types.
Preview release of standard and extensible API proxies
Apigee announces the Preview release of standard and extensible API proxies, available for use with preview organizations using Pay-as-you-go (updated attributes) pricing.
For more information about standard and extensible API proxies, see API proxy types.
Preview release of new HTTPModifier and ReadPropertySet policies and templating support for message <URL> elements
Apigee announces the Preview release of the HTTPModifier and ReadPropertySet policies.
The HTTPModifier policy can change an existing request or response message and provides a subset of the functionality already available in the AssignMessage policy. See HTTPModifier policy.
The ReadPropertySet policy reads property sets and populates flow variables with the results. See ReadPropertySet policy.
HTTPModifier and ReadPropertySet are standard policies. Proxies built exclusively with standard policies are called standard proxies and can be deployed to any environment type. See Pay-as-you-go (updated attributes) pricing overview.
This release also includes template support for message <URL> elements. See URL templating.
Spanner Data Boost lets you execute analytics queries and data exports with near-zero impact to existing workloads on your provisioned Spanner instance. This feature is now generally available (GA) in the following regions:
- asia-northeast1 (Tokyo)
- us-central1 (Iowa)
- southamerica-east1 (São Paulo)
- europe-west1 (Belgium)
- europe-west2 (London)
- europe-west3 (Frankfurt)
When you create dashboards, you can make use of the following enhancements to UDM Events Explore:
- Search and navigation improvements. When you navigate or search for events in UDM Events Explore, the results appear instantly and field names are easy to identify.
- Improvements to field names and descriptions. The field names and path are now consistent with the pattern used in Detection Engine rules and UDM search. For example, the field name
Udm Events Principal Hostnamenow appears asUDM principal.hostnameas in documentation. Also, in addition to online help, in-context descriptions are available for UDM fields. For example, deprecated fields are indicated by the suffix [D] in the field name. - User experience improvements in UDM Events Explore. When you use UDM Events Explore, user experience is improved by removing unused and rarely used fields. Also, you can filter based on the grouped fields.
- Field conversion improvements. Added fields that automatically handle conversion of formats. Here are some examples:
- Enum fields also contain human readable values. For example, the values for the
UDM.network.ip_protocolenum also appear as ICMP, TCP, and UDP instead of 1, 2, and 3. - Timestamp fields are available in multiple date formats. Previously, timestamp fields were available only in nano and second formats.
- Location fields are parsed accurately and can be used in maps.
- Enum fields also contain human readable values. For example, the values for the
- Report improvements. Made data in reports up-to-date by using the
eventstable in BigQuery. Also, existing reports that previously usedudm_eventswill use theeventstable.
The following resource types are now publicly available through the Export APIs (ExportAssets, ListAssets, and BatchGetAssetsHistory), Feed API, and Search APIs (SearchAllResources, SearchAllIamPolicies).
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- Cloud KMS
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
The Cloud Load Balancing Console now allows you to see the equivalent API code for actions you take in the Console. When you create or update a load balancer, before you click Create or Update, you can click Equivalent Code to view the load balancer API resources that will be created, updated, or deleted.
This capability is in General Availability.
The Google Cloud console can now automatically install the Ops Agent for you when you create a VM instance. During the installation process, the Compute Engine VM Manager creates an Ops Agent OS policy that installs the agent and reinstalls it when necessary. For more information, see Install the Ops Agent during VM creation.
The Google Cloud console can now automatically install the Ops Agent for you when you create a VM instance. During the installation process, the Compute Engine VM Manager creates an Ops Agent OS policy that installs the agent and reinstalls it when necessary. For more information, see Install the Ops Agent during VM creation.
Cloud SQL now supports non-RFC 1918 IP address ranges, including privately used public IP addresses. This enables you to create instances and replicas in a non-RFC 1918 IP address range. Additionally, you can connect to an instance from an application that is running in a non-RFC 1918 IP address range.
Cloud SQL now supports non-RFC 1918 IP address ranges, including privately used public IP addresses. This enables you to create instances and replicas in a non-RFC 1918 IP address range. Additionally, you can connect to an instance from an application that is running in a non-RFC 1918 IP address range.
Cloud SQL now supports non-RFC 1918 IP address ranges, including privately used public IP addresses. This enables you to create instances and replicas in a non-RFC 1918 IP address range. Additionally, you can connect to an instance from an application that is running in a non-RFC 1918 IP address range.
Generally available: You can now use a regional Persistent Disk as a VM boot disk.
New Dataproc Serverless for Spark runtime versions:
- 1.1.22
- 2.0.30
- 2.1.9
Dialogflow CX conversation history has been promoted from Preview to GA (generally available).
Dialogflow CX minimum voice session duration for pricing has been decreased from 1 minute to 1 second.
Backup disk updates for SAP HANA deployment automation
While automating the deployment of SAP HANA scale-up systems on Google Cloud using Terraform, the following updates are available for hosting the /hanabackup volume on a disk:
- You can use the
backup_disk_typeargument to specify the type of Persistent Disk or Hyperdisk that must be deployed. - For compatibility across all machine families, the default disk type has been changed from Standard HDD Persistent Disk to Balanced Persistent Disk.
These updates are available when you use the sap_hana and sap_hana_ha Terraform modules, version 202307061058 or later, provided by Google Cloud.
For more information, see the deployment guide for your SAP HANA scenario.
Vertex AI model evaluation is now generally available (GA) with the following new Preview features:
- Model evaluation with sliced metrics.
- Model evaluation with fairness and bias metrics.
- Vision error analysis for AutoML image classification models.
Support to define environment variables at deployment time is available in Preview. See the blog post: Custom Environment Variables in Workflows.
July 05, 2023
AlloyDB for PostgreSQLThe extension pgvector has been added to the extensions supported by AlloyDB. For more information, see Announcing vector support in PostgreSQL services to power AI-enabled applications.
The issue relating to Application Integration setup failure in a new Google Cloud project has been resolved.
BigQuery is now available in the Turin (europe-west12) and Doha (me-central1) regions.
You can use the LOAD DATA SQL statement to load data from Avro, CSV, newline delimited JSON, JSON, ORC, or Parquet files into a table. This feature is generally available (GA).
The slot estimator now provides cost-optimal commitment and autoscale recommendations based on editions pricing and historical performance metrics. This feature is in preview.
The fail-safe period is now generally available (GA). The fail-safe period offers an additional seven days of data storage after the time travel window, so that the data is available for emergency recovery. Billed costs won't include the bytes used for fail-safe storage until July 17th, 2023.
The ability to use physical bytes for storage billing is now generally available (GA). When you set your dataset's storage billing model to use physical bytes, the total active storage costs you are billed for includes the bytes used for time travel and fail-safe storage. For more information, see Dataset storage billing models.
The ability to configure the time travel window is now generally available (GA). You can specify the duration of the time travel window from a minimum of two days to a maximum of seven days.
BigQuery capacity commitments have changed as follows:
- Annual commitments are now only available in Enterprise or Enterprise Plus edition. Flat-rate annual commitments are no longer available. For more information about pricing, see Capacity compute (analysis) pricing.
- Monthly and flex commitments are no longer available. For more information about commitment options, see Capacity commitment plans.
You can now restrict data egress on Analytics Hub listings. This feature is now in preview.
Enhancements to outcome section in rules:
Outcome variables can be used to derive the value of another outcome variable.
Arithmetic expressions can include aggregations, unaggregated event fields, constants, and outcome variables as operands.
Long running jobs greater than 1 hour are now supported (in Preview).
cos-dev-109-17727-0-0
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.1.35 | v23.0.3 | v1.7.2 | v470.182.03(default),v525.105.17 |
Upgraded sys-apps/coreutils to v9.3.
Upgraded sys-apps/less to v633-r1.
Upgraded sys-fs/e2fsprogs to v1.47.0-r2.
cos-101-17162-210-48
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Fixed CVE-2020-27619, CVE-2021-3177 and CVE-2022-45061 in python.
Fixed CVE-2019-10160, CVE-2019-9948 and CVE-2019-9636 in python2.
Fixed CVE-2023-3268 in the Linux kernel.
cos-105-17412-101-42
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.109 | v23.0.3 | v1.7.0 | v470.182.03(default),v525.105.17 |
Fixed CVE-2023-3268 in the Linux kernel.
cos-93-16623-402-40
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Fixed CVE-2023-3268 in the Linux kernel.
Dialogflow CX now provides prebuilt components, which are prebuilt flows that handle common scenarios and accelerate agent development.
The following Dialogflow CX features have been promoted from Preview to GA (generally available):
You can use Policy Troubleshooter to troubleshoot deny policies. This feature is in Preview.
Moving a reserved external IPv4 address from one project to another is available in General Availability.
reCAPTCHA Enterprise Mobile SDK v18.2.2 is now available for iOS.
This version contains a speculative fix for the race condition that was occurring in execute(). For more information about the issue, see Crash when executing token request.
July 04, 2023
Certificate Authority ServiceCertificate Authority Service now supports Workforce identity federation.
Cloud Composer 2 is now available in Tel Aviv (me-west1).
Cloud Workstations is available in the australia-southeast1 region (Sydney, Australia, APAC). For more information, see Locations.
July 03, 2023
BatchSamples in C++ are available for Batch. Documentation has been updated to include the following samples:
- Create a basic container job
- Create a basic script job
- Create and run a job that uses storage volumes
- Define job resources using a VM instance template
- Delete a job
- View a list of your jobs
- View the details of a job
- View a list of a job's tasks
- View the details of a task
- View logs for a job
For more information, see All Batch code samples.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for bigquery/storage/apiv1beta1
1.52.0 (2023-06-23)
Features
- bigquery/storage: Add estimated physical file sizes to ReadAPI v1 (94ea341)
- bigquery/storage: Add table sampling to ReadAPI v1 (ca94e27)
- bigquery: Support for tables primary and foreign keys (#8055) (93d6a1a)
- bigquery: Update all direct dependencies (b340d03)
Bug Fixes
Python
Changes for google-cloud-bigquery
3.11.3 (2023-06-27)
Bug Fixes
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigtable
2.24.1 (2023-06-27)
Bug Fixes
2.24.0 (2023-06-27)
Features
- Add experimental reverse scan for public preview (#1809) (f4f2e2e)
- Reverse scans public preview (#1711) (176360f)
Dependencies
- Update dependency com.google.truth.extensions:truth-proto-extension to v1.1.5 (#1801) (a8961e8)
- Update dependency kr.motd.maven:os-maven-plugin to v1.7.1 (#1792) (80acca0)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.23 (#1800) (a9172c4)
- Update shared dependencies to 3.12.0, monitoring to 3.21.0, update renovate config (#1807) (12fc8cd)
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for datastore/admin/apiv1
1.12.0 (2023-06-27)
Features
- datastore: Update all direct dependencies (b340d03)
Bug Fixes
- datastore: Change aggregation result to return generic value (#8167) (9d3d17b)
- datastore: Handling nil slices in save and query (#8043) (36f01e9)
- datastore: PKG:datastore TYPE:datastoreClient FUNC:RunAggregationQuery (#7803) (1f050ea)
- datastore: REST query UpdateMask bug (df52820)
- datastore: Update grpc to v1.55.0 (1147ce0)
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for pubsub/apiv1
1.32.0 (2023-06-27)
Features
- pubsub: Add push config wrapper fields (ca94e27)
- pubsub: Add support for cloud storage subscriptions (#7977) (54218e9)
- pubsub: Enable project autodetection and detect empty project (#8168) (c7e05d8)
- pubsub: Update all direct dependencies (b340d03)
Bug Fixes
- pubsub/pstest: Align fake handling of bqconfig subscription to server behavior (#8066) (57914ec)
- pubsub/pstest: Fix failing bq config test (#8060) (fb9db66)
- pubsub: Fix issue preventing clearing BQ subscription (#8040) (0366bf3)
- pubsub: REST query UpdateMask bug (df52820)
- pubsub: Use fieldmask directly instead of field_mask genproto alias (#8030) (087a5fc)
Documentation
- pubsub: Tightened requirements on cloud storage subscription filename suffixes (1da334c)
Java
Changes for google-cloud-pubsub
1.123.17 (2023-06-26)
Dependencies
1.123.16 (2023-06-26)
Dependencies
June 30, 2023
Access ApprovalAccess Approval supports Memorystore for Redis in the Preview stage.
Vectorized join is available in Preview. Part of the AlloyDB columnar engine, vectorized join can improve the performance of joins by applying vectorized processing to qualifying queries.
Fault injection lets you test the resilience of a cluster's primary instance by simulating a sudden outage of its active node. This triggers the AlloyDB high availability feature that automatically promotes the instance's standby node to become the new active node.
hybrid v1.10
On June 30, 2023 we released an updated version of the Apigee hybrid software, v1.10.0.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.10.
- For information on new installations, see The big picture.
Pre-install Cluster Check Kubernetes job
Starting in version 1.10, Apigee hybrid offers a new tool that examines the hybrid cluster before you install the hybrid runtime. See Step 8: Check cluster readiness .
Automated Issue Surfacing (AIS)
Starting with Apigee hybrid 1.10, Apigee hybrid offers a new tool that examines the hybrid runtime and surfaces issues by running a kubectl command. If the tool detects errors in the cluster, it returns a detailed error message. The error message contains a link to the troubleshooting guide for that specific error. See Automated issue surfacing and Configuration property reference, watcher.
Support for AppGroups (preview)
Starting in version 1.10, Apigee hybrid supports AppGroups, which represent a relationship between one or more apps that are managed by the same set of people. For information, see Using AppGroups to organize app ownership.
AppGroups is in preview as of the Apigee hybrid 1.10 release. See the AppGroups preview launch announcement for details.
Support for environment-level scaling
Starting in version 1.9.3, Apigee hybrid added the following environment configuration properties that enable you to specify environment-specific scaling in the overrides.yaml file:
envs[].runtime.replicaCountMaxenvs[].runtime.replicaCountMinenvs[].synchronizer.replicaCountMaxenvs[].synchronizer.replicaCountMinenvs[].udca.replicaCountMaxenvs[].udca.replicaCountMin
Documentation: Environment-based scaling
| Bug ID | Description |
|---|---|
| 181569522 | You can now create a new environment with the same name as a deleted environment without needing to perform manual clean-up tasks first. (Fixed in Apigee hybrid v1.8.5 and v1.7.6) |
| 209509030 | Apigee Ingressgateway cannot access K8s secret from another namespace. |
| 218567150 | The ingress gateway is now configured to consistently preserve UUID in the x-request-id header. Note: This setting does have some impact on tracing in the ingress gateway. For more information, see pack_trace_reason in "UUID (proto)" in the envoy documentation. (Fixed in Apigee hybrid v1.7.6 and v1.8.3) |
| 223320630 | mTLS-related client variables are now set by the Apigee runtime. (Fixed in Apigee hybrid v1.8.6) |
| 245619397 | In Apigee hybrid, fluentbit support now includes the NO_PROXY environment variable. (Fixed in Apigee hybrid v1.8.5, v1.8.6, and v1.9.1) |
| 259264961 | Added support for ASM v1.15. Please see Known issue 266452840 (Fixed in Apigee hybrid v1.7.6) |
| 260342163 | Fixed a narrow scenario where threads in runtime pods ended up consuming 100% CPU. (Fixed in Apigee hybrid v1.9.1) |
| 260372012 | Requests failed with 500 response and keyvaluemap.service.ErrorDuringDecryption error after upgrade to Hybrid 1.8. Note: Fixed in Apigee hybrid 1.8.4 and newer. (Fixed in Apigee hybrid v1.8.5) |
| 262699558 | The watcher component no longer fails when using Kubernetes Secret to store hybrid service account secret. (Fixed in Apigee hybrid v1.7.6) |
| 263840644 | Fixed a conflict with an existing ASM on the cluster. (Fixed in Apigee hybrid v1.8.6) |
| 265374889 | Fixed an issue where in some circumstances the Java Callout would to fail due with the following error: Failed to execute JavaCallout. Could not initialize class org.jose4j.jwa.AlgorithmFactoryFactory2. (Fixed in Apigee hybrid v1.9.1) |
| 266411394 | Add support for Azure Front Door request headers to /healthz health check. (Fixed in Apigee hybrid v1.8.5 and v1.9.1) |
| 266594584 | Websocket was failing in asm 1.15. This was due to incompatible capitalization in variable names between the Anthos Service Mesh overlay.yaml file and the and the Envoy filter apigee-envoyfilter.yaml file. (Fixed in Apigee hybrid v1.8.5 and v1.9.1) |
| 266814873 | In certain circumstances, retrieving encrypted KVM entries could fail with an error. This fix ensures that MART will be able to successfully function for environment-scoped KVM entries, even if the encryption key is used in the Org Env configuration or when the keys contain non-UTF8 characters. There is no change to KVM data. (Fixed in Apigee hybrid v1.8.6 and v1.9.1) |
| 266989915 266919136 |
In some circumstances, Apigee could return incorrect developer credentials for an app, unless the specific app was selected when requesting the credentials. (Fixed in Apigee hybrid v1.9.1) |
| 267666187 | When using a custom Kubernetes service for the Apigee ingress gateway, you can disable the creation of a default load balancer. See Managing Apigee ingress gateway. (Fixed in Apigee hybrid v1.8.6 and v1.9.1) |
| 267691299 265295406 |
The Apigee controller uses a dedicated apigee-manager Kubernetes service account, instead of using the default SA. (Fixed in Apigee hybrid v1.8.6 and v1.9.1) |
| 268445095 | The validateOrg flag can be set to false to bypass upgrade validation errors when configuration includes HTTP Forward proxy. You can use this to avoid upgrade errors caused by HTTP proxy settings. (Fixed in Apigee hybrid v1.7.6) |
| 268696297 | Providing a Kubernetes secret for Cassandra and Redis components is now supported. See cassandra.auth.secret and redis.auth.secret in the Configuration properties reference. (Fixed in Apigee hybrid v1.9.1) |
| 269451743 | In certain circumstances, upgrading from Apigee hybrid v1.8.3 to v1.9.0 could fail with an error message when creating the virtual hosts. (Fixed in Apigee hybrid v1.9.1) |
| 269738951 | The example network policies are now included in the apigeectl/examples/network-policies directory. see Configuring Kubernetes network policies. (Fixed in Apigee hybrid v1.9.1) |
| 270371160 | In Apigee hybrid v1.8.7, we removed certain insecure TLS ciphers. Apigee hybrid supports the TLS cipher suites supported by the Boring FIPS build of Envoy. You can now specify specific cipher suites with the virtualhosts.cipherSuites configuration property in your overrides. (Fixed in Apigee hybrid v1.8.7) Note: Apigee hybrid only supports the RSA ciphers listed. ECDSA ciphers are not supported. |
| 270371160 | In Apigee hybrid v1.9.0, we removed certain insecure TLS ciphers. Apigee hybrid supports the TLS cipher suites supported by the Boring FIPS build of Envoy. You can now specify specific cipher suites with the virtualhosts.cipherSuites configuration property in your overrides. (Fixed in Apigee hybrid v1.9.2) Note: Apigee hybrid only supports the RSA ciphers listed. ECDSA ciphers are not supported. |
| 271266079 | Removed port 80 from the default Kubernetes service of Apigee Ingress Gateway. (Fixed in Apigee hybrid v1.8.6 and v1.9.1) |
| 272212164 | Cassandra CSI backup could clash with Azure default configuration. The CSI backup script has been fixed to prevent a resource naming issue that could cause backups to fail. (Fixed in Apigee hybrid v1.8.7 and v1.9.2) |
| 273561434 | Some projects were unable to run debug sessions.. (Fixed in Apigee hybrid v1.8.8) |
| 274292101 | In certain circumstances, environment-scoped KVMs in hybrid could cause rollback issues for MART. (Fixed in Apigee hybrid v1.8.6) |
| 274999014 | Restrict watcher RBAC to a single K8s namespace |
| 278646149 | In certain circumstances, the logger.livenessProbe.timeoutSeconds configuration property was not working as expected. See logger.livenessProbe.timeoutSeconds in the Configuration property reference. (Fixed in Apigee hybrid v1.8.7 and v1.9.2) |
| 279053612 | x-forwarded-client-cert (XFCC) HTTP headers handled with the istiod.forwardClientCertDetails configuration property. (Fixed in Apigee hybrid v1.8.7 and v1.9.2) See the Configuration properties reference for details: |
| 279193831 | Envoy has been updated to v1.25.6.. (Fixed in Apigee hybrid v1.8.8) |
| 279712107 | Added the ability to annotate apigee-ingressgateway-manager pods through overrides.yaml file. (Fixed in Apigee hybrid v1.8.8) |
| 280544499 | Request headers were not seen in debug sessions. (Fixed in Apigee hybrid v1.8.8) |
| 284488296 | Removed an unneeded Workload Identify on the Cassandra Schema Validation cron job. (Fixed in Apigee hybrid v1.8.8 and v1.9.3) |
| Bug ID | Description |
|---|---|
| 270371160 | In Apigee hybrid v1.9.0, we removed certain insecure TLS ciphers. Apigee hybrid supports the TLS cipher suites supported by the Boring FIPS build of Envoy. Note: Apigee hybrid only supports the RSA ciphers listed. ECDSA ciphers are not supported. |
| 271266079 | Removed port 80 from the default Kubernetes service of Apigee Ingress Gateway. Port 80 is not supported by Apigee ingress gateway. If you are migrating from ASM to Apigee ingress gateway, and followed the instructions in the community post to enable Port 80, it will not work with Apigee Ingress gateway. (Fixed in Apigee hybrid v1.8.6 and v1.9.1) |
| Bug ID | Description |
|---|---|
| 262576079 | Security fix for for apigee-envoy. (Fixed in Apigee hybrid v1.10)This addresses the following vulnerability: |
| 273797045 | Security fix for for apigee-diagnostics-collector apigee-synchronizer apigee-udca. (Fixed in Apigee hybrid v1.8.8)This addresses the following vulnerability: |
| 273800345, 281572616 | Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, apigee-synchronizer, and apigee-udca. (Fixed in Apigee hybrid v1.8.8 and v1.9.3This addresses the following vulnerabilities: |
| 273800717 | Security fixes for apigee-emulator, apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-mock-server, apigee-runtime, and apigee-synchronizer. (Fixed in Apigee hybrid v1.8.7 and v1.9.2)This addresses the following vulnerabilities: |
| 273800965 | Security fix for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. (Fixed in Apigee hybrid v1.8.7, v1.9.2, and v1.9.3)This addresses the following vulnerability: |
| 273801301 | Security fixes for apigee-mart-server and apigee-runtime.(Fixed in Apigee hybrid v1.8.8 and v1.9.3)This addresses the following vulnerability: |
| 274112103 | Security fixes to the Apigee Controller and Apigee Watcher. (Fixed in Apigee hybrid v1.8.6 and v1.9.1) This addresses the following vulnerabilities: |
| 275002360 | Security fixes for fluent-bit. (Fixed in Apigee hybrid v1.8.6 and v1.9.1)This addresses the following vulnerabilities: |
| 277367440 | Security fixes for Apigee Controller, Watcher, and apigeectl. (Fixed in Apigee hybrid v1.8.7 and v1.9.2)This addresses the following vulnerabilities: |
| 278313047 | Security fixes for apigee-stackdriver-logging-agent. (Fixed in Apigee hybrid v1.9.2)This addresses the following vulnerabilities: |
| 279194142 | Fixes build issues to achieve FIPS compliance. (Fixed in Apigee hybrid v1.8.7 and v1.9.2) |
| 281561243 | Security fix for apigee-diagnostics-collector, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. (Fixed in Apigee hybrid v1.8.8 and v1.9.3)This addresses the following vulnerability: |
| 283826216 | Security fixes for apigee-ingressgateway. (Fixed in Apigee hybrid v1.9.3)This addresses the following vulnerabilities: |
| 283826785 | Security fixes for istiod. (Fixed in Apigee hybrid v1.9.3)This addresses the following vulnerabilities: |
Go repositories are now generally available.
Storage and network egress charges apply to all formats that are generally available.
The EU Regions and Support with Sovereignty Controls compliance program now supports the following products. See Supported products for more information:
- Artifact Registry
- BigQuery
- Cloud Composer
- Dataproc
The IL5 compliance program is now generally available.
Metadata caching is now available for BigLake tables that reference Amazon S3 data. This feature is in preview. Using cached metadata might improve query performance for BigLake tables.
Reverse scans in Cloud Bigtable are now available in Preview. For details, see Reverse scans.
The maximum retention period for a Cloud Bigtable backup has been increased from 30 days to 90 days, giving you more robust data protection and data quality control. This feature is generally available (GA). For more information on how Bigtable backups work, see About backups.
You can use custom constraints to provide more granular and customizable control over specific fields for VPC firewall rule resources. For more information, see Manage firewall resources by using custom constraints. This feature is available in Preview.
For our preferred partners and allowlisted customers, Private Service Connect is now available. This solution allows you to connect to a Cloud SQL instance from multiple VPC networks that belong to different groups, teams, projects, or organizations. To use Private Service Connect, contact your Technical Account Manager.
For our preferred partners and allowlisted customers, Private Service Connect is now available. This solution allows you to connect to a Cloud SQL instance from multiple VPC networks that belong to different groups, teams, projects, or organizations. To use Private Service Connect, contact your Technical Account Manager.
You can suspend and resume E2 VMs.
ServiceNow is now available as a native, fully integrated CRM, providing a more efficient and streamlined configuration process that includes embedded agent adapters. Previously, ServiceNow could only be integrated using the Generic API Custom CRM solution. For details, see the ServiceNow integration documentation.
External Storage dynamic folder path and filename formats: CCAIP offers this new capability for the External Storage configuration feature. Dynamic folder path and filename formats offer more flexibility for storing your call recordings, chat transcripts, voicemails, photos, videos, and co-browsing files. You can now include run-time variables like {DATE}, {SESSION_ID}, and {SESSION_TYPE} in the path and configure custom filename formats with sub-paths. See the documentation for details.
Alvaria WFM integration is now available as an out-of-the box data export. You can enable it using Developer Settings > Session Data Export > Manage Data Export Settings. You have the option of exporting either a basic session data report at intervals of 15, 30 or 60 minutes, or a daily agent productivity report. The reports can be delivered to either a Google Cloud or Amazon S3 storage bucket.
Call recordings separated by segments: You can now choose to receive one recording per call segment instead of all call segments in a single recording. Separate call recordings allow more flexible call analysis and more efficient issue resolution. See the Queue and menu settings documentation for details.
Resolved an intermittent issue that allowed a call to be transferred to a queue during hours that it should not have been available.
Resolved a bug that caused the custom holiday feature to throw a "Can't create root directory" error and not be able to save or create holidays.
Support for ENUM and CITEXT data types is now added for PostgreSQL sources.
Support for revert snapshot operations is now available for high scale SSD instances (Preview).
Enterprise Search: Image search
Search for images on your website. Provide an image (Base64 encoded PNG, JPG, or BMP) as the query and use an API method to return similar images.
For more information, see Search for images using a website search engine.
Enterprise Search: Extractive answers
Extractive answers are available in preview. An extractive answer is verbatim text that is returned with each search result. This text is extracted directly from the search result document and is typically displayed near the top of web pages to provide an end user with a brief answer that is contextually relevant to their query.
For more information, see Use snippets and extracted content.
Enterprise Search: Extractive segments
Extractive segments are available in preview. An extractive segment is verbatim text that is returned with each search result and is usually more verbose than an extractive answer. Extractive segments can be displayed as an answer to a query and be used in post-processing tasks and as input for large language models to generate answers or new text.
For more information, see Use snippets and extracted content.
Enterprise Search: OCR processing
Optical character recognition (OCR) processing is available, improving parsing and segmentation of PDF files at data ingestion. This enables Gen App Builder to take into account structures such as paragraphs and tables when ingesting your documents, providing more accurate search results, snippets, and summarizations. To request this functionality, contact your Google Cloud account team.
For more information, see OCR processing.
This is a patch release of Google Distributed Cloud Edge (version 1.4.1).
The following changes have been introduced in this release of Distributed Cloud Edge:
- The IP addresses of local control plane endpoints are now accessible on your local network. You must ensure that your local network's security configuration prevents external access to those IP addresses.
The following issues have been resolved in this release of Distributed Cloud Edge:
- Resource utilization metrics that were previously not exported to Cloud Monitoring are now exported as expected.
- The status of the
kube-apiservermirrored Pods is no longer erroneously reported as "Pending."
Firewall and database IP address change
As announced on July 14, 2022, the IP addresses used by Looker Studio to connect to the following databases have changed:
- Amazon Redshift
- MySQL
- PostgreSQL
- Microsoft SQL Server 2017
The IP addresses to use are:
- 142.251.74.0/23
- 2001:4860:4807::/48 (Optional, for platforms that support IPv6)
You may close any of the previously listed addresses. They are no longer used by Looker Studio.
Improvements to bar and combo charts
You can configure the following options for bar charts and combo charts with bars from the STYLE tab of the properties panel:
- For stacked bar charts, 100% stacked bar charts, and combo charts with stacked bars, you can choose between the default Metric value label type and the Stacked label type. For stacked bar charts, you can also choose the Total label type.
- You can use the Bar label position setting to specify the position of the bar label relative to the bars or columns in the chart.
- In the Chart spacing section, you can define custom spacing between bars and groups of multiple bars.
- You can select the Bar border color icon to choose a custom color for bar or column borders.
Learn more about bar charts and combo charts.
Audit logging for team workspaces
You can now view Team Workspace log events in the Admin Console (Security Investigation Tool). To see these events, filter the log by choosing Team Workspace as the asset type.
Learn more about Looker Studio log events.
Media Translation is deprecated and will no longer be available on Google Cloud after July 1, 2024. Migrate your applications to Cloud Speech-to-Text and Cloud Translation to replicate the functionality of Media Translation.
The following products are now supported. See Supported products for more information:
- Artifact Registry
- BigQuery
- Cloud Composer
- Dataproc
Vertex Explainable AI
Support for example-based explanations is now generally available (GA).
Vertex AI data labeling is deprecated and will no longer be available on Google Cloud after July 1, 2024. For new labeling tasks, you can use add labels using the Google Cloud console or access data labeling solutions from our partners in the Google Cloud Console Marketplace, such as Labelbox and Snorkel.
You can use custom constraints to provide more granular and customizable control over specific fields for some VPC resources. For more information, see Manage VPC resources by using custom constraints. This feature is available in Preview.
Support for invoking a VPC Service Controls-compliant private endpoint is available in Preview.
Three functions are available: map.merge takes two maps, creates a copy of the first map, and adds items from the second map to the copy; map.merge_nested recursively adds items from a map to a copy of another map; uuid.generate returns a random universally unique identifier.
June 29, 2023
Access ApprovalAccess Approval supports Application Integration in the Preview stage.
Release 1.13.9
Anthos clusters on bare metal 1.13.9 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.13.9 runs on Kubernetes 1.24.
Fixes:
The following container image security vulnerabilities have been fixed:
ISSUE Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
AML AI is generally available with release version v1.
The API supports the following capabilities:
- Model tuning through
engineConfigresources - Backtesting and prediction using a model
- Exporting metadata from an engine config, model, backtest, or prediction resource
The ITAR compliance program now supports BigQuery. See Supported products for more information.
Support for the following compliance programs is now generally available (GA):
Google has added Israel (Tel Aviv) as a new region for Chronicle customers. Chronicle can now store customer data in this region. This also adds a new regional endpoint for Chronicle APIs at https://me-west1-backstory.googleapis.com.
A new metric was added to monitor exit_codes of task runners: composer.googleapis.com/workflow/task_runner/terminated_count.
Improved the error message when environment creation fails because of issues with GKE workloads.
(Airflow 2.4.3) Logs produced in Airflow DAG callbacks are now visible in Cloud Logging under the "DAG processor manager" logs section. This feature was previously available only in images with Airflow 2.5.1.
(Airflow 2.4.3) Changed the severity of triggerer watchdog messages from error to warning and updated the message's content to be more informative. This feature was previously available only in images with Airflow 2.5.1.
Cloud Composer 2.3.3 images are available:
- composer-2.3.3-airflow-2.5.1 (default)
- composer-2.3.3-airflow-2.4.3
Cloud Composer versions 2.0.19, 2.0.18, 1.19.2, and 1.19.1 have reached their end of full support period.
Preview: c3-standard and c3-highmem machine types are now available for general-purpose C3 VMs.
cos-105-17412-101-37
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.109 | v23.0.3 | v1.7.0 | v470.182.03(default),v525.105.17 |
Added support for GPUDirect-TCPX.
Runtime sysctl changes:
- Changed: vm.lowmem_reserve_ratio: 256 256 32 0 -> 256 256 32 0 0
cos-97-16919-294-48
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.176 | v20.10.14 | v1.6.20 | v470.182.03(default),v525.105.17 |
Upgraded sys-apps/file to v5.43-r1 to fix CVE-2019-18218.
Fixed CVE-2023-3268 in the Linux kernel.
cos-101-17162-210-44
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Fixed CVE-2022-37454 in python.
Upgraded sys-apps/file to v5.43-r1 to fix CVE-2019-18218.
cos-93-16623-402-39
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Upgraded sys-apps/file to v5.43-r1 to fix CVE-2019-18218.
Container Registry API requests that reference a non existent project respond with 403 (permission denied) instead of 400 (bad request) status.
New Dataproc Serverless for Spark runtime versions:
- 1.1.21
- 2.0.29
- 2.1.8
Added support for Premium compute and storage pricing tiers for Dataproc Serverless Spark workloads. Premium compute offers higher performance per core, and Premium storage offers higher throughput and IOPs. To use Premium compute and storage, set the following Spark runtime environment properties:
spark.dataproc.(driver|executor).compute.tier=premiumspark.dataproc.(driver|executor).storage.tier=premium.
Identity Document AI (IDAI) photo copy detection in ID proofing (Preview)
Updated the pretrained-id-proofing-v1.1-2023-05-18 ID proofing processor for all Document AI users.
This processor includes a new output entity fraud_signals_photocopy_detection that signals if an attached image might be a photocopy. The entity can be one of the following values: POSSIBLE_PHOTOCOPY, PASS, or INCONCLUSIVE.
Generally Available: Migrate to Virtual Machines lets you migrate your VM instances running on Google Cloud VMware Engine to VM instances running on Compute Engine.
Vertex AI Codey APIs
The Vertex AI Codey APIs are now generally available (GA). Use the Codey APIs to create solutions with code generation, code completion, and code chat. Because the Vertex AI Codey APIs are GA, you incur usage costs if you use them. To learn about pricing, see the Generative AI support on Vertex AI pricing page.
The models in this release include:
code-bison(code generation)codechat-bison(multi-turn code chat)code-gecko(code completion)
The maximum tokens for input was increased from 4,096 to 6,144 tokens for code-bison and codechat-bison to allow longer prompts and chat history. The maximum tokens for output was increased from 1,024 to 2,048 for code-bison and codechat-bison to allow for longer responses.
Additional programming languages are supported. For more information, see Supported coding languages.
Several fine-tuning datasets were removed from the code-bison and codechat-bison models to implement the following improvements:
- Excessive chattiness.
- Artifacting, such as NBSP (non-breaking space) characters.
- Low quality code responses.
To learn about cloud horizontals, please see Vertex AI certifications.
Vertex AI Pipeline task-level logs are now generally available (GA) in Cloud Logging. Additionally, from Cloud Logging you can route pipeline logs to a Pub/Sub sink to power your event-driven architecture. For more information, see View pipeline job logs.
June 28, 2023
Anthos Config ManagementThe constraint template library includes a new template: K8sRequireBinAuthZ. For reference, see the Constraint template library.
The constraint template library includes a new template: K8sRestrictAutomountServiceAccountTokens. For reference, see the Constraint template library.
The constraint template library includes a new template: K8sRestrictRoleRules. For reference, see the Constraint template library.
Fixed a formatting issue in nomos status --name. For more information, see nomos status flags.
The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.
- AIX system (
AIX_SYSTEM) - Auth0 (
AUTH_ZERO) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS GuardDuty (
GUARDDUTY) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS Session Manager (
AWS_SESSION_MANAGER) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Check Point (
CHECKPOINT_FIREWALL) - Chrome Management (
N/A) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Meraki (
CISCO_MERAKI) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Stealthwatch (
CISCO_STEALTHWATCH) - CrowdStrike Falcon (
CS_EDR) - Digi modems (
DIGI_MODEMS) - GitHub (
GITHUB) - IBM Security Verify SaaS (
IBM_SECURITY_VERIFY_SAAS) - Imperva (
IMPERVA_WAF) - Infoblox DNS (
INFOBLOX_DNS) - Jamf Protect Alerts (
JAMF_PROTECT) - Jamf Protect Telemetry (
JAMF_TELEMETRY) - Kisi Access Management (
KISI) - Kubernetes Audit Azure (
KUBERNETES_AUDIT_AZURE) - Kubernetes Node (
KUBERNETES_NODE) - Linux Auditing System (AuditD) (
AUDITD) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - McAfee MVISION CASB (
MCAFEE_MVISION_CASB) - McAfee Skyhigh CASB (
MCAFEE_SKYHIGH_CASB) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Microsoft AD (
WINDOWS_AD) - Microsoft AD FS (
ADFS) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Exchange (
EXCHANGE_MAIL) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Office 365 (
OFFICE_365) - Open Cybersecurity Schema Framework (OCSF) (
OCSF) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Security Command Center Threat (
N/A) - Static IP (
ASSET_STATIC_IP) - Symantec Web Security Service (
SYMANTEC_WSS) - ThreatLocker Platform (
THREATLOCKER) - Tripwire (
TRIPWIRE_FIM) - VMware NSX (
VMWARE_NSX) - VMware vRealize Suite (
VMWARE_VREALIZE) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Zscaler (
ZSCALER_WEBPROXY)
For details about changes in each parser, see Supported default parsers.
The Cloud Bigtable metric Five-second maximum requests per minute is now generally available (GA). This metric measures the maximum number of requests received in a five-second span per minute to help you identify short bursts of traffic. For a full description, see Metrics.
The CROATIA_PERSONAL_ID_NUMBER infoType detector is available in all regions. For more information about all built-in infoTypes, see InfoType detector reference.
Global external Application Load Balancers now support outlier detection for serverless NEG backends. Outlier detection analysis identifies unhealthy serverless NEGs based on their HTTP response patterns, and reduces the error rate by routing some of the new requests from unhealthy services to healthy services. For more details, see the following topics:
You can now have a maximum of 10 HMAC keys per service account.
Generally Available: Persistent Disk Asynchronous Replication (PD Async Replication) is now generally available. For more information, see About Persistent Disk Asynchronous Replication.
New Dataproc on Compute Engine subminor image versions:
- 2.0.68-debian10, 2.0.68-rocky8, 2.0.68-ubuntu18
- 2.1.16-debian11, 2.1.16-rocky8, 2.1.16-ubuntu20
Backported ZEPPELIN-5755 to Zeppelin 0.10 in 2.1 images for Spark 3.3 support.
Dialogflow CX now supports flow scoped parameters.
The following document OCR features are Generally Available (GA). Use document OCR's configurations to optimize for stability, quality, and specific response requirements.
- Intelligent Document Quality Analysis
- Native Text from Digital PDF
- Symbol level extraction
- Language hints
Support for DOCX is in Preview. You can synchronously process DOCX files that are up to 15 pages, or asynchronously process DOCX files that are up to 30. For access, send us a request.
Added fixes to our doc.proto-to-vision.proto conversion tool, which facilitates migration from Vision API Text Detection to document OCR
The document OCR native text from digital PDF feature contains the following known issues:
- For a small number of documents, word order in lines of text that are reported by native text extraction might be inaccurate.
- Invisible text that is embedded in a native PDF might be extracted.
- Japanese documents that contain currency symbols, such as Yen, might be incorrectly extracted as
/. - Apostrophe symbols might be missing in word and/or line results.
- Native text extraction might report different word and/or line results compared to image-based OCR on an identical document.
Google Cloud VMware Engine now supports ESXi syslog forwarding, including distributed firewall logs, which provides more visibility into security events on VMware Engine instances. VMware Engine is also releasing additional security controls that will enable you to manage permissions elevation.
This enhanced security model gives you more granular control over how Google support staff access your VMware Engine instances for workloads that require additional controls due to regulatory or compliance reasons. Please contact support for assistance with configuring these services.
Google Cloud VMware Engine now supports Terraform for private cloud, cluster, and network management. This release covers Create, Update, and Delete commands for private cloud resources. The VMware Engine Terraform provider enables Infrastructure-as-Code for your VMware Engine Environment.
To learn more about these new features and how to get started, please visit the VMware Engine documentation on the Hashicorp site and review the IaC Foundations blueprint.
FQDN Network Policy, currently in Public Preview, can now be enabled on GKE Autopilot clusters, by updating your clusters. To lean more, see Control Pod egress traffic using FQDN network policies.
As of June 20, 2023, Security Command Center Asset API endpoints and dependent functionality are deprecated and will be removed from the product for all users on or after June 20, 2024. Use Cloud Asset Inventory and its API instead.
After June 20, 2023, the asset functionality is not included with new activations of Security Command Center.
If you activated Security Command Center before June 20, 2023, but have not used the asset functionality in the 90 days prior to June 20, 2023, the asset functionality is removed.
If you activated Security Command Center before June 20, 2023, and have used the asset functionality in the 90 days prior to June 20, 2023, the asset functionality remains available for you until June 20, 2024 or later.
The deprecation applies to the following Security Command Center interfaces:
- Security Command Center Asset API endpoints
- Except for
gcloud scc assets update-marks, which is not deprecated, theassetssubgroup of thegcloud sccCLI command - The Assets page and related functionality in the Google Cloud Console
Studio voices now support SSML, except for the following tags: <mark>, <emphasis>, <prosody>, and <lang>
June 27, 2023
AlloyDB for PostgreSQLIAM authentication for AlloyDB is available in Preview. You can add a role to Identity and Access Management (IAM) user or service accounts that lets them log into AlloyDB instances as database users.
The columnar engine now supports columns with the following data types:
booleanbyteaenumuuid
With CVE-2023-31436, an out-of-bounds memory access flaw was found in the Linux kernel's traffic control (QoS) subsystem in how a user triggers the qfq_change_class function with an incorrect MTU value of the network device used as lmax. This flaw allows a local user to crash or potentially escalate their privileges on the system.
For more information, see the GCP-2023-017 security bulletin.
A new vulnerability (CVE-2023-2235) has been discovered in the Linux kernel that can lead to a privilege escalation on the node. For more information, see the GCP-2023-018 security bulletin.
With CVE-2023-31436, an out-of-bounds memory access flaw was found in the Linux kernel's traffic control (QoS) subsystem in how a user triggers the qfq_change_class function with an incorrect MTU value of the network device used as lmax. This flaw allows a local user to crash or potentially escalate their privileges on the system.
For more information, see the GCP-2023-017 security bulletin.
A new vulnerability (CVE-2023-2235) has been discovered in the Linux kernel that can lead to a privilege escalation on the node. For more information, see the GCP-2023-018 security bulletin.
Security bulletin
A number of vulnerabilities have been discovered in Envoy, which is used in Anthos Service Mesh (ASM). These were reported separately as GCP-2023-002.
For more information, see the GCP-2023-016 security bulletin.
Security bulletin
With CVE-2023-31436, an out-of-bounds memory access flaw was found in the Linux kernel's traffic control (QoS) subsystem in how a user triggers the qfq_change_class function with an incorrect MTU value of the network device used as lmax. This flaw allows a local user to crash or potentially escalate their privileges on the system.
For more information, see the GCP-2023-017 security bulletin.
Security bulletin
A new vulnerability (CVE-2023-2235) has been discovered in the Linux kernel that can lead to a privilege escalation on the node. For more information, see the GCP-2023-018 security bulletin.
Security bulletin (all minor versions)
A number of vulnerabilities have been discovered in Envoy, which is used in Anthos Service Mesh (ASM). These were reported separately as GCP-2023-002.
For more information, see the GCP-2023-016 security bulletin.
On June 27, 2023 we released an updated version of Apigee X.
Public preview of AppGroups
Introduces the concept of AppGroups, which represent a relationship between one or more apps that are managed by the same set of people. For information, see Using AppGroups to organize app ownership.
Note that the purpose of this release is to support upgrades from Apigee Edge customers who used company-apps without monetization; however, it is available to any Apigee X/hybrid customer during the public preview stage.
The default generic builder now uses the Ubuntu 22 LTS base image. When you specify the latest location, the builds now uses the google-22 builder by default. For example, you can specify either of the following to use google-22:
gcr.io/buildpacks/builder:latestgcr.io/buildpacks/builder:google-22
If you need to pin your build to the previous Ubuntu 18 builder, see the instructions about how to configure the builder version, including:
packcommands for local builds.gcloudcommands for remote builds.- How to configure the
project.tomlfor Cloud Run.
You can now enable batch write flow control when you use Dataflow to send batch writes to Cloud Bigtable. This generally available (GA) feature automatically rate-limits traffic to avoid cluster overload and works with Bigtable autoscaling to ensure the optimal number of nodes is available to handle the batch write. For more information, see Batch write flow control.
Cloud Functions now supports performance recommendations that analyze cold starts and suggest setting up minimum instances to improve function performance at the General Availability release level.
Generally available: NVIDIA A100 80GB GPUs are now available in the following additional regions and zones:
- Ohio, North America:
us-east5-b
For more information about using GPUs on Compute Engine, see GPU platforms.
Config Controller now uses the following versions of its included products:
- Config Connector v1.105.0, release notes
- Anthos Config Management v1.15.1, release notes
Dialogflow CX has added the following system functions:
- IS_CREDIT_CARD_NUMBER
- IS_DATE
- IS_FUTURE_DATE
- IS_PAST_DATE
- IS_PHONE_NUMBER
- NESTED_FIELD
- ROUND
- TO_OBJECT
- TO_PHONE_NUMBER
- UPPER
Eventarc events and Firestore in Datastore mode events for Cloud Functions (2nd gen) now available in Preview.
With CVE-2023-31436, an out-of-bounds memory access flaw was found in the Linux kernel's traffic control (QoS) subsystem in how a user triggers the qfq_change_class function with an incorrect MTU value of the network device used as lmax. This flaw allows a local user to crash or potentially escalate their privileges on the system.
For more information, see the GCP-2023-017 security bulletin.
A new vulnerability (CVE-2023-2235) has been discovered in the Linux kernel that can lead to a privilege escalation on the node. For more information, see the GCP-2023-018 security bulletin.
(2023-R14) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- Version 1.26.5-gke.1200 is now the default version.
- The following control plane and node versions are now available:
- The following node versions are now available:
- The following control plane versions are no longer available:
- 1.23.17-gke.2000
- 1.23.17-gke.3600
- 1.25.8-gke.500
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.23.17-gke.5600 with this release.
Stable channel
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.22.17-gke.8000
- 1.23.17-gke.2000
- 1.24.12-gke.500
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.12-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.24.12-gke.1000 with this release.
Regular channel
- Version 1.26.5-gke.1200 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.22.17-gke.11400
- 1.23.17-gke.5600
- 1.24.12-gke.1000
- 1.25.8-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.26.5-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
Rapid channel
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.23.17-gke.6800
- 1.24.14-gke.1400
- 1.25.10-gke.1200
- 1.26.5-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.7000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
(2023-R14) Version updates
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.22.17-gke.8000
- 1.23.17-gke.2000
- 1.24.12-gke.500
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.12-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.24.12-gke.1000 with this release.
(2023-R14) Version updates
- Version 1.26.5-gke.1200 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.22.17-gke.11400
- 1.23.17-gke.5600
- 1.24.12-gke.1000
- 1.25.8-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.26.5-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
(2023-R14) Version updates
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.23.17-gke.6800
- 1.24.14-gke.1400
- 1.25.10-gke.1200
- 1.26.5-gke.1200
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.7000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.2100 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.1400 with this release.
(2023-R14) Version updates
- Version 1.26.5-gke.1200 is now the default version.
- The following control plane and node versions are now available:
- The following node versions are now available:
- The following control plane versions are no longer available:
- 1.23.17-gke.2000
- 1.23.17-gke.3600
- 1.25.8-gke.500
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.23.17-gke.5600 with this release.
On June 27, 2023 we released version 1.2.0 of the Migrate to Containers modernization plugins.
Learn how to Upgrade Migrate to Containers plugins.
The following issues were fixed:
- Unsupported Apache module caused the migration to get stuck in the generate artifacts phase.
- Duplicate migration warnings appeared for JBoss Wildfly workloads.
- Duplicate
sensitiveDataPathentries found in JBoss Wildfly migration plan.
Transfers from Amazon S3 no longer require s3:GetBucketLocation permission on the source bucket.
For a full list of required permissions, see Configure access to a source: Amazon S3.
The Video Stitcher API now requires that a live stream source manifest references at least one valid segment file. The manifest is specified in the live config's sourceUri field.
June 26, 2023
Access ApprovalAccess Approval supports Eventarc in the GA stage.
On June 26, 2023 Apigee API hub released a new version of the software.
API hub has been upgraded to use a later version of the Registry API open-sourced project. See v0.6.13 on GitHub for changes and links to previous revisions that are also included in this update. Note that this update (like all previous updates), overwrites project-level artifacts that configure API hub displays including display settings, taxonomies, and lifecycles. In future releases, we will no longer overwrite project-level artifacts.
Node.js 20 is now generally available. Note that Node.js 20 enters long-term support (LTS) in October and is the Node.js "Current" version until that time. We encourage you to explore the new features and benefits included in this release to evaluate their potential impact on your applications. For more information, see the Node.js 20 announcement .
PHP 7.4, 8.1, and 8.2 are now available in preview. These versions require you to specify an operating system version in your app.yaml file. Learn more.
The Node.js 20 runtime for App Engine standard environment is now generally available. Note that Node.js 20 enters long-term support (LTS) in October and is the Node.js "Current" version until that time. We encourage you to explore the new features and benefits included in this release to evaluate their potential impact on your applications. For more information, see the Node.js 20 announcement .
Data Transformer Script task (Preview)
The Data Transformer Script task is a template engine based data mapping feature available in Application Integration. With the Data Transformer Script task and the supported Data Transformer functions, you can create and evaluate custom Jsonnet templates in order to perform data mapping in your integration.
For more information, see Data Transformer Script task.
You can now create stored procedures for Apache Spark using Java or Scala. You can also use the Google Cloud console PySpark editor to add options for stored Python procedures for Apache Spark. This feature is in Preview.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.29.0 (2023-06-23)
Features
Dependencies
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.12.0 (#2771) (7537e0f)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.23 (#2759) (27ba48a)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.23 (#2760) (8cddf8f)
2.28.0 (2023-06-19)
Features
Python
Changes for google-cloud-bigquery
3.11.2 (2023-06-21)
Bug Fixes
Address groups are a logical collection of either IPv4 address ranges or IPv6 address ranges in CIDR format. You can use address groups to define consistent sources or destinations referenced across multiple rules in the same or different firewall policies. This feature is available in General Availability.
The Node.js 20 runtime is now available for Google Cloud Functions at the GA release level. Note that Node.js 20 will enter long-term support (LTS) in October and is the Node.js "Current" release until then. The Node.js community encourages you to explore the new features and benefits included in this release. For more information, see the Node.js 20 announcement.
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-logging
3.15.5 (2023-06-22)
Dependencies
3.15.4 (2023-06-22)
Dependencies
Cloud SQL now supports SQL Server 2022. The default version continues to be SQL Server 2019 Standard. For more information, see Database versions and version policies.
A monthly digest of client library updates from across the Cloud SDK.
Go
Changes for spanner/admin/database/apiv1
1.47.0 (2023-06-20)
Features
- spanner/admin/database: Add DdlStatementActionInfo and add actions to UpdateDatabaseDdlMetadata (01eff11)
- spanner: Add databoost property for batch transactions (#8152) (fc49c78)
- spanner: Add tests for database roles in PG dialect (#7898) (dc84649)
- spanner: Enable client to server compression (#7899) (3a047d2)
- spanner: Update all direct dependencies (b340d03)
Bug Fixes
Java
Changes for google-cloud-spanner
6.43.0 (2023-06-07)
Features
- Delay transaction start option (#2462) (f1cbd16)
- Make administrative request retries optional (#2476) (ee6548c)
Dependencies
Node.js
Changes for @google-cloud/spanner
6.11.0 (2023-06-06)
Features
- spanner: Add DdlStatementActionInfo and add actions to UpdateDatabaseDdlMetadata (#1860) (3e86f36)
- Testing for fgac in pg (#1811) (c48945f)
6.12.0 (2023-06-19)
Features
Python
Changes for google-cloud-spanner
3.36.0 (2023-06-06)
Features
Generally available: For managed instance groups (MIGs), Google Cloud Console provides you with an improved way to configure autoscaling based on Cloud Monitoring metrics. The redesigned user interface enables you to explore available metrics and filters. You can visualize the metric values in a chart, which also displays the aggregated value used for autoscaling.
cos-dev-109-17722-0-0
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.1.35 | v23.0.3 | v1.7.2 | v470.182.03(default),v525.105.17 |
Updated sosreport to v4.5.4.
Updated google-guest-configs to v20230526.00.
Updated toolbox to v20230615.
Upgraded app-misc/ca-certificates to v20230311.3.90.
Upgraded net-misc/curl to v8.1.2.
Upgraded app-misc/mime-types to v2.1.54.
Disabled CONFIG_DEBUG_CREDENTIALS in the kernel due to its performance impact on some container workloads.
Updated open-vm-tools to v12.2.5 to fix CVE-2023-20867.
Updated dev-lang/go to v1.20.5. This fixes CVE-2023-29403, CVE-2023-29404, CVE-2023-29402 and CVE-2023-29405.
cos-105-17412-101-36
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.109 | v23.0.3 | v1.7.0 | v470.182.03(default),v525.105.17 |
Updated google-guest-configs to v20230526.00.
Updated toolbox to v20230615.
Updated dev-lang/go to v1.20.5. This fixes CVE-2023-29403, CVE-2023-29402, CVE-2023-29405 and CVE-2023-29404.
Fix CVE-2023-1972 in binutils.
Fix CVE-2023-1972 in binutils-libs.
Fixed CVE-2023-34256 in the Linux kernel.
cos-97-16919-294-44
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.176 | v20.10.14 | v1.6.20 | v470.182.03(default),v525.105.17 |
Updated google-guest-configs to v20230526.00.
Updated toolbox to v20230615.
Fix CVE-2023-1972 in binutils.
Fixed CVE-2023-34256 in the Linux kernel.
cos-101-17162-210-40
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Updated google-guest-configs to v20230526.00.
Updated toolbox to v20230615.
Updated dev-lang/go to 1.19.10. This fixes CVE-2023-29403, CVE-2023-29404, CVE-2023-29402 and CVE-2023-29405.
cos-93-16623-402-36
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Updated cloud-udev-nvme-config to v20230526.00.
Updated toolbox to v20230615.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for dataflow/apiv1beta3
0.9.1 (2023-06-20)
Bug Fixes
- dataflow: REST query UpdateMask bug (df52820)
Added Dataproc Serverless Templates for batch creation:
- Cloud Storage to BigQuery
- Cloud Storage to Cloud Spanner
- Hive to Cloud Storage
- JDBC to BigQuery
- JDBC to Cloud Storage
M109 release
- Pytorch 2.0 with Python 3.10 and CUDA 11.8 container images are now available.
- Miscellaneous software updates.
M109 release
- Pytorch 2.0 on Debian 11 with Python 3.10 and CUDA 11.8 images are now available.
- GPU-based Deep Learning VM Images now installs Nvidia drivers with the new open kernel modules if started on an A2 or G2 machine instead of the proprietary kernel modules.
- Miscellaneous software updates.
A weekly digest of client library updates from across the Cloud SDK.
Python
Changes for google-cloud-datastore
2.16.0 (2023-06-21)
Features
Java
Changes for google-cloud-datastore
2.16.0 (2023-06-22)
Features
Dependencies
Cloud Deploy support for parallel deployment is now generally available.
Cloud Deploy support for the canary deployment strategy is now generally available.
Pay-as-you-go (PAYG) licenses for Windows Server are now available in Preview.
Managed Service for Prometheus is enabled by default in new GKE Standard clusters running version 1.27 and later. Existing clusters that upgrade to 1.27 will not automatically enable this feature. For more information, see Enable managed collection: GKE.
Starting June 26, 2023, Cloud DNS becomes the default DNS provider for new GKE Autopilot clusters created with version 1.25.9-gke.400 or later or version 1.26.4-gke.500 or later, effectively replacing kube-dns. To learn more, see Cloud DNS for GKE.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-pubsub
1.123.15 (2023-06-22)
Bug Fixes
Documentation
Dependencies
- Update dependency com.google.cloud:google-cloud-bigquery to v2.27.0 (#1599) (3b4b7d0)
- Update dependency com.google.cloud:google-cloud-bigquery to v2.27.1 (#1614) (a974e08)
- Update dependency com.google.cloud:google-cloud-bigquery to v2.28.0 (#1626) (a4a02b4)
- Update dependency com.google.cloud:google-cloud-core to v2.20.0 (#1629) (5f88f4f)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.12.0 (#1630) (b444a9d)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.23 (#1623) (b5f8e49)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.23 (#1624) (68ada24)
- Update dependency org.xerial.snappy:snappy-java to v1.1.10.1 - abandoned (#1616) (48ec282)
- Update dependency org.xerial.snappy:snappy-java to v1.1.10.1 security (a1cb267)
Retail API: Data export for analytics and other use cases is in GA
Exporting retail data into BigQuery is now generally available (GA), allowing you to extract insights from your data. You can use the data to get Key Performance Indicators with our out-of-the-box Looker dashboard, and sales forecasts using Vertex AI and our step-by-step instructions.
Entities are available as a way to subdivide your retail organization into more than one segment. For example, entities can represent different regions where stores are located or differently branded stores, such as acquisitions. Recommendations, search results, and autocomplete can give results tailored specifically for an entity.
For more information, see Entities.
The Data quality page assesses the quality of your product catalog and user event data and shows you which search performance tiers you have unlocked for Retail Search.
For more information, see Unlock search performance tiers.
The Data quality page replaces the Data Quality panel which was on the Retail console Data page.
Cloud Storage Backint agent for SAP HANA version 1.0.26
Version 1.0.26 of the Cloud Storage Backint agent for SAP HANA is available. This version includes updated libraries and bug fixes.
For more information about the agent, see Cloud Storage Backint agent for SAP HANA overview.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for secretmanager/apiv1
1.11.1 (2023-06-20)
Bug Fixes
- secretmanager: REST query UpdateMask bug (df52820)
M109 release
The M109 release of Vertex AI Workbench user-managed notebooks includes the following:
- Pytorch 2.0 with Python 3.10 and CUDA 11.8 user-managed notebooks instances are now available.
- Miscellaneous software updates.
The M109 release of Vertex AI Workbench managed notebooks includes the following:
- Fixed a bug that caused high cpu utilization due to excessive internal diagnostic tool processes.
- Fixed a bug that was showing incorrect kernel image icons in the Jupyterlab launcher.
Support for Customer-Managed Encryption Keys (CMEK) is generally available (GA).
June 23, 2023
Anthos clusters on bare metalRelease 1.14.6
Anthos clusters on bare metal 1.14.6 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.14.6 runs on Kubernetes 1.25.
Functionality changes:
- Upgraded etcd version to v3.4.26-0-gke.0.
Fixes:
The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
On April 20, 2023 we released an updated version of Apigee integrated portal. The fix below was not reported in a release note at the time. This update corrects the record.
| Bug ID | Description |
|---|---|
| 275578252 | Addressed an issue where an account could be created even though the built-in identity provider (IdP) had been disabled. For any portal with a disabled IdP, you can review the user accounts on the Portals > Portal name > Accounts > Users page. Select an account and then change the Status to Inactive to prevent login. Documentation: Deactivating user accounts |
The Chronicle Data in BigQuery feature, including the export pipeline and events table, has been improved. Data for the
events table is stored as parquet files in Google Cloud Storage which provides
more flexibility for users who want to export data. See Chronicle documentation
for more information about
data export to BigQuery,
the
events table,
and the
BigQuery Access API.
The Cloud Build Security insights panel that displays security metrics such as Supply-chain Levels for Software Artifacts (SLSA) level for built artifacts, vulnerabilities, and build details is now generally available.
Cloud Build now provides the ability to upload npm packages to Artifact Registry automatically and generate Supply-chain Levels for Software Artifacts (SLSA) Level 3 build provenance. This feature is generally available. For more information, see Build and test Node.js applications.
The Java runtime now supports projects that use Maven wrappers.
Cloud Spanner Data Boost lets you execute analytics queries and data exports with near-zero impact to existing workloads on your provisioned Spanner instance. This feature is now generally available (GA) in the following regions:
- asia-northeast1 (Tokyo)
- asia-south1 (Mumbai)
- us-central1 (Iowa)
- nam3 (North America)
- southamerica-east1 (São Paulo)
- europe-west-1 (Belgium)
- europe-west2 (London)
- europe-west3 (Frankfurt)
For more information, see Data Boost overview.
Objects created using XML API multipart uploads can now be copied and rewritten normally.
- Previously, you had to perform an object composition on such objects before the output could be copied or rewritten.
Preview: You can now use custom constraints to provide more granular and customizable control over specific fields for some Compute resources. For more information, see Manage Compute Engine resources using custom constraints.
Fixed the bug where plain_text is overritten during document creation.
Eventarc support for creating triggers for direct events from the following sources is available in Preview:
- AlloyDB for PostgreSQL
- Backup for GKE
- Cloud Dataplex
- Dataproc Metastore
- GKE Hub
- Google Cloud Memorystore for Redis
- Network Connectivity
- Network Management
- User-managed notebooks (Notebooks)
- Vision AI
- VM Migration
Automatic GPU driver installation is available in version 1.27.2-gke.1200 and later, which enables you to install NVIDIA GPU drivers on nodes without manually applying a DaemonSet.
For instructions, see Running GPUs.
June 22, 2023
Anthos clusters on bare metalRelease 1.15.2
Anthos clusters on bare metal 1.15.2 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.2 runs on Kubernetes 1.26.
Functionality changes:
Added preflight check to make sure control plane and load balancer nodes aren't in maintenance mode before an upgrade.
Upgraded etcd version to v3.4.26-0-gke.0.
Fixes:
Fixed an issue where containerd didn't restart when there was a version mismatch. This issue caused an inconsistent containerd version within the cluster.
Fixed an issue where the
spec.proxy.noProxyvalue wasn't used in the Google Cloud connectivity preflight check (bmctl check gcp).Fixed an issue that caused the logging agent to use continuously increasing amounts of memory. The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
The Java runtime now supports using Maven wrappers for managing your project's dependency on Maven.
The Java runtime now supports using Maven wrappers for managing your project's dependency on Maven.
The Java runtime now supports using Maven wrappers for managing your project's dependency on Maven.
You can now share a dashboard file between instances or within an instance between different users. The dashboard can be shared without manually creating copies.
The predefined reference lists for Curated Detections have been replaced by rule exclusions. You will see the following changes:
- Reference lists are not available in the Cloud Threats and Windows Threats categories and are not displayed in the settings page for these rule sets.
- Any category-specific reference lists that were currently empty have been deleted.
- Any category-specific reference lists that were not empty have been migrated to an equivalent rule exclusion.
You can now use rule exclusions to tune the number of alerts returned by Curated Detections.
Spanner Vertex AI integration is now generally available. You can use Vertex AI with GoogleSQL to enhance your Spanner applications with machine learning capabilities. For more information, see About Spanner Vertex AI integration.
New Dataproc Serverless for Spark runtime versions:
- 1.1.20
- 2.0.28
- 2.1.7
You can now prevent Cloud Deploy from overprovisioning GKE and Anthos pods during a canary deployment.
GKE Autopilot now supports the ability to deploy your own service mesh. Many service meshes, such as Istio or LinkerD, require CAP_NET_ADMIN Linux capability to function, which is disabled on Autopilot clusters by default to reduce the size of the security attack surface. You can now optionally enable NET_ADMIN on your Autopilot clusters if you need this capability for your service meshes or other opt-in use cases. See Autopilot Security for more information for how to enable NET_ADMIN.
You can trigger service agent creation instead of waiting for service agents to be created automatically. This feature is in Preview.
Only the Security Center Service Agent (roles/securitycenter.serviceAgent) role is required by the Security Command Center service account. Previously, the service account also required the roles/serviceusage.serviceUsageAdmin and roles/cloudfunctions.serviceAgent roles to work properly.
Preview stage support for the following integration:
June 21, 2023
AlloyDB for PostgreSQLAlloyDB cross-region replication is generally available (GA).
TRUNCATE TABLE is now supported for multi-statement transactions. This feature is now generally available (GA).
Certificate Authority Service is now available in the following regions:
- me-central1
- europe-west12
For more information, see Certificate Authority Service locations.
We're announcing the rebranding of Cloud Load Balancing into two main types of load balancers: Application Load Balancers and Network Load Balancers.
Over the past few years, we've undertaken several initiatives to bring greater consistency across all flavors of Cloud Load Balancing - for example, by making Envoy proxy the consistent data plane for all new load balancing features. Now, to further help our users understand the different features available with Cloud Load Balancing, and help them quickly identify the best type of load balancer for their use-case, we're adopting a new naming convention.
What is the new naming convention?
Cloud Load Balancing now offers two types of load balancers: Application Load Balancers and Network Load Balancers. As a general rule, you'd choose an Application Load Balancer when you need a Layer 7 load balancer for your applications with HTTP(S) traffic. You'd choose a Network Load Balancer when you need a Layer 4 (TCP) load balancer that supports TLS offloading (with a proxy load balancer) or you need support for additional IP protocols such as UDP (with a passthrough load balancer).
Application and Network Load Balancers can be configured in various deployment modes, for example, internal (private networks) or external (internet facing), global or regional.
For more details, see the following topics:
The Google Cloud Console has also been updated to reflect these changes. No changes have been made to the API.
The following Google Cloud CLI commands are generally available (GA):
gcloud workstationsgcloud workstations configsgcloud workstations clusters
Stretched Private Clouds are now available in the following region:
- London, England, Europe (
europe-west2)
Stretched Private Clouds allow you to stretch your vSphere/vSAN clusters across Google Cloud zones and protect against zone-level failures. This functionality enables high levels of availability for business critical applications.
A new vulnerability, CVE-2023-0468, has been discovered in the Linux kernel that could allow an unprivileged user to escalate privileges to root when io_poll_get_ownership will keep increasing req->poll_refs on every io_poll_wake then overflow to 0 which will fput req->file twice and cause a struct file refcount issue. GKE clusters, including Autopilot clusters, with Container-Optimized OS using Linux Kernel version 5.15 are affected. GKE clusters using Ubuntu images or using GKE Sandbox are unaffected.
For instructions and more details, see the GKE security bulletin.
GKE support for Hyperdisk Throughput and Hyperdisk Extreme as an attached persistent disk option is now generally available. Support is available for both Autopilot and Standard clusters running GKE versions 1.26 and later.
Event Threat Detection, a built-in service of Security Command Center, released the following new rules to General Availability.
Initial Access: Dormant Service Account ActionPrivilege Escalation: Dormant Service Account Granted Sensitive RolePersistence: Impersonation Role Granted For Dormant Service AccountInitial Access: Dormant Service Account Key Created
For more information, see Event Threat Detection rules.
June 20, 2023
Access ApprovalAccess Approval supports Cloud Run in the Preview stage.
The extension anon has been added to extensions supported by AlloyDB.
Security bulletin
A new vulnerability, CVE-2023-0468, has been discovered in the Linux kernel that could allow an unprivileged user to escalate privileges to root when io_poll_get_ownership will keep increasing req->poll_refs on every io_poll_wake then overflow to 0 which will fput req->file twice and cause a struct file refcount issue. GKE clusters, including Autopilot clusters, with Container-Optimized OS using Linux Kernel version 5.15 are affected. GKE clusters using Ubuntu images or using GKE Sandbox are unaffected.
For more information, see the GCP-2023-015 security bulletin.
On June 20, 2023, we released an updated version of Apigee X (1-10-0-apigee-4).
| Bug ID | Description |
|---|---|
| 284114575 | Implemented fix to prevent the execution of untrusted code in Apigee policies. |
| 279092925 | Modified Cloud Logging policy to improve runtime performance. |
| 186885918 | Disabled access to external entities in XML parsing. |
| 270764083 | Default expiration for refresh tokens set to 30 days if not explicitly set in the OAuth policy. |
| N/A | Upgraded infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 273801301 | Security fix for apigee-diagnostics-collector, apigee-mart-server, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerabilities: |
| 281561243 | Security fix for apigee-diagnostics-collector, apigee-mart-server, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerabilities: |
You can now view storage volume and LUN metrics in the Google Cloud console. This feature is in preview.
You can now rename your Bare Metal Solution resources, including servers, networks, storage volumes, and NFS shares. This feature is generally available (GA).
Cloud Client Libraries for C++ are available for the Batch API. For more information, see the reference documentation.
Metadata caching is now generally available (GA). Using cached metadata might improve query performance for BigLake tables and object tables that reference large numbers of objects, by allowing the query to avoid listing objects from Cloud Storage.
This release includes support for the following new features:
- Protecting metadata cache data with customer-managed encryption keys.
- Statistics on metadata cache usage.
- Table statistics for better query plan performance.
Metadata cache usage is billed going forward. For more information, see Costs.
BigQuery now supports querying Apache Iceberg tables that are created by open source engines. This feature is now generally available (GA).
(Airflow 2.5.1 only) Logs produced in Airflow DAG callbacks are now visible in Cloud Logging in the "DAG processor manager" logs section.
DataprocSubmitJobOperator now supports data lineage for Hive, SparkSQL, Presto, and Trino jobs.
(Airflow 2.5.1) Changed the severity of triggerer watchdog messages from error to warning and updated the message's content to be more informative. This change improves debugging experience for triggers.
Cloud Composer 2.3.2 images are available:
- composer-2.3.2-airflow-2.5.1 (default)
- composer-2.3.2-airflow-2.4.3
Database Migration Service support for PostgreSQL to AlloyDB for PostgreSQL migrations is now generally available (GA).
Log buckets in the following regions can now be upgraded to use Log Analytics:
- asia-east1
- europe-north1
- northamerica-northeast2
- us-east4
For more information, see Supported regions.
cos-93-16623-402-30
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Fixed CVE-2023-1972 in binutils.
Fixed CVE-2023-1972 in binutils-libs.
Fixed CVE-2023-34256 in the Linux kernel.
cos-101-17162-210-32
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Fixed CVE-2023-1972 in binutils.
Fixed CVE-2023-1972 in binutils-libs.
Fixed CVE-2023-34256 in the Linux kernel.
OR queries now supported at the General Availability level.
OR queries are now supported at the General Availability level.
DDoS attack visibility is now available in public preview. For more information, see Access DDoS attack visibility telemetry.
Network edge security polices are now available in public preview to allowlisted users. For more information about network edge policies, see Types of security policies. In addition, you can learn how to Configure network edge security policies.
You can now use VPC Service Controls to secure your live streams.
General availability for the following integration:
A100 80GB accelerators are now generally available (GA) for custom training jobs in the following regions:
- asia-southeast1
- europe-west4
- us-central1
- us-east4
For more information, see Locations.
The Google Cloud Pipeline Components (GCPC) SDK v2 is now generally available (GA). GCPC v2 introduces support for the KFP v2 SDK and is fully supported by Vertex AI Pipelines.
To learn more about the updates in the latest version of the GCPC SDK, see the Google Cloud Pipelines Components Release Notes.
The Kubeflow Pipelines (KFP) SDK v2 is now generally available (GA). KFP SDK v2 introduces several improvements for authoring pipelines and is fully supported by Vertex AI Pipelines.
To learn more about the changes in KFP v2, see the KFP v2 Release Notes and KFP v2 migration guide.
The connection preference for a Private Service Connect published service can be configured on the VPC network level in addition to project level. For more information, see Publish a service with explicit approval. This feature is available in General Availability.
Service consumers can use organization policies with the compute.restrictPrivateServiceConnectProducer list constraint to block Private Service Connect endpoints and backends from connecting to service attachments in other organizations. For more information, see Block endpoints and backends from connecting to unauthorized service attachments.
Service producers can use organization policies with the compute.restrictPrivateServiceConnectConsumer list constraint to control which endpoints and backends can connect to Private Service Connect service attachments within a producer organization or project. For more information, see Block unauthorized endpoints and backends from connecting to service attachments.
These constraints are available in General Availability.
June 19, 2023
BigQueryA weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.27.1 (2023-06-13)
Dependencies
- Update actions/checkout action to v3.5.3 (#2746) (17f8438)
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.21.0 (#2741) (d665e52)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.25.0 (#2743) (5d38d23)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.11.0 (#2738) (3b56445)
- Update github/codeql-action action to v2.20.0 (#2751) (42ae181)
- Update github/codeql-action action to v2.3.6 (#2712) (f043ed6)
Python
Changes for google-cloud-bigquery
3.11.1 (2023-06-09)
Documentation
Filtering the compiled graph in a workspace is available.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-datastore
2.15.0 (2023-06-09)
Features
Bug Fixes
Dependencies
A weekly digest of client library updates from across the Cloud SDK.
An issue with how Workflows handles HTTP headers with duplicate keys is resolved. The values associated with duplicate header keys are merged into a comma-separated list as described in RFC 9110. Previously, all but one of the values associated with duplicate keys would be dropped.
June 16, 2023
AlloyDB for PostgreSQLAlloyDB for PostgreSQL is now available in europe-west9 (Paris). For more information, see AlloyDB Locations.
Security bulletin
Two new security issues were discovered in Kubernetes where users may be able to launch containers that bypass policy restrictions when using ephemeral containers and either ImagePolicyWebhook (CVE-2023-2727) or the ServiceAccount admission plugin (CVE-2023-2728).
For more information, see the GCP-2023-014 security bulletin
Security bulletin (all minor versions)
Two new security issues were discovered in Kubernetes where users may be able to launch containers that bypass policy restrictions when using ephemeral containers and either ImagePolicyWebhook (CVE-2023-2727) or the ServiceAccount admission plugin (CVE-2023-2728).
For more information, see the GCP-2023-014 security bulletin.
On June 16, 2023 Apigee API hub released a new version of the software.
API hub has been upgraded to use a later version of the Registry API open-sourced project. See v0.6.12 on GitHub for changes and links to previous revisions that are also included in this update.
Note that artifacts associated with API spec and deployment resources are now associated with the revisions of those resources. This allows artifacts that represent lint results and other revision-specific characteristics to be associated with those revisions. When artifacts are applied directly to the parent resource (spec or deployment), these artifacts are associated with the latest revisions of these resources. For more details, see this GitHub issue.
Migration of pre-existing spec- and deployment-related artifacts is not guaranteed in this update. In most cases, these artifacts are generated automatically by the registry controller and will be automatically recreated. If you find that manually-added artifacts are missing after the update, those will need to be reapplied with the same mechanisms that were available previously.
A new Google Cloud Threat Intelligence (GCTI) data source is available, called GCTI Remote Access Tools, that provides additional contextual information when investigating activity in your environment. This data source contains files that have frequently been used by malicious actors. For more information, see Data about remote access tools, and Query data about remote access tools.
Cloud Functions 2nd gen now supports deterministic URLs (similar to 1st gen), at the General Availability release level. This change will not just affect new 2nd gen functions. Previously deployed 2nd gen functions will be retroactively assigned a deterministic cloudfunctions.net URL. The function's previous run.app URL will continue to work also. If your 2nd gen function was last deployed before June 15th, 2023, be sure to redeploy it before using cloudfunctions.net URL as an auth token audience.
CCAI Platform now supports the CCAI Insights feature. You can use CCAI Insights to detect and visualize patterns in your contact center data. See the documentation for details.
New Dataproc on Compute Engine subminor image versions:
- 2.0.67-debian10, 2.0.67-rocky8, 2.0.67-ubuntu18
- 2.1.15-debian11, 2.1.15-rocky8, 2.1.15-ubuntu20
Fixed a bug that caused cluster creation to fail when ATSv2 is enabled for tables that have a garbage collection policy setup other than maxversions.
Add support to filter for empty integer and float typed properties.
Two new security issues were discovered in Kubernetes where users may be able to launch containers that bypass policy restrictions when using ephemeral containers and either ImagePolicyWebhook (CVE-2023-2727) or the ServiceAccount admission plugin (CVE-2023-2728).
For more information, see the GCP-2023-014 security bulletin.
GA4 API dimensions/metrics
New Google Analytics 4 data sources that you create get their fields directly from the GA4 API. Previously, GA4 data sources were based on a fixed schema with a predefined list of fields. To see new fields from the GA4 API in an existing data source, refresh the fields.
Learn how connect to Google Analytics.
Documentation update
Updated Connect to Google Analytics. Added information and links about the GA4 schema change, and the deprecation of Universal Analytics. Removed information about connecting to Universal Analytics.
You can now monitor how custom constraints would impact your organization's workflows by setting custom constraints in dry-run mode.
June 15, 2023
BigQueryThe following Generative AI features are now in preview with allowlist:
- Creating a remote model based on the Vertex AI large language model (LLM)
text-bison. - Using the
ML.GENERATE_TEXTfunction with an LLM-based remote model to perform generative natural language tasks on text stored in BigQuery tables.
Try these features with the Generate text by using a remote model and the ML.GENERATE_TEXT function tutorial.
The following resource types are now publicly available through the Export APIs (ExportAssets, ListAssets, and BatchGetAssetsHistory), Feed API, and Search APIs (SearchAllResources, SearchAllIamPolicies).
- CloudTasks
The following resource types are now publicly available through the analyze policy APIs (AnalyzeIamPolicy and AnalyzeIamPolicyLongrunning).
- Workflows
Cloud Composer 2.3.1 release started on June 15, 2023. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet.
Cloud Composer 2 is now available in Columbus (us-east5).
Cloud Composer 2.3.1 images are available:
- composer-2.3.1-airflow-2.5.1 (default)
- composer-2.3.1-airflow-2.4.3
Cloud Composer versions 2.0.17 and 1.19.0 have reached their end of full support period.
The Cloud SQL System insights dashboard helps you detect and analyze system performance problems.
The Cloud SQL System insights dashboard is now generally available and includes more metrics. You can also use the Customize dashboard option to personalize the dashboard and choose the metrics you want to see on it.
Cloud Asset Inventory support for Cloud Tasks is now in Preview. For details, see the Cloud Asset Inventory release note.
(2023-R13) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- Version 1.25.8-gke.1000 is now the default version.
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.21.14-gke.18100
- 1.24.11-gke.1000
- 1.26.4-gke.500
- 1.26.4-gke.1400
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to version 1.21.14-gke.18800 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.21.14-gke.18800 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
Stable channel
- The following versions are now available in the Stable channel:
- Version 1.24.11-gke.1000 is no longer available in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
Regular channel
- Version 1.25.8-gke.1000 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.22.17-gke.8000
- 1.23.17-gke.2000
- 1.25.8-gke.500
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.11400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
Rapid channel
- Version 1.27.2-gke.1200 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.11400
- 1.23.17-gke.5600
- 1.24.14-gke.1200
- 1.25.9-gke.2300
- 1.26.3-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
(2023-R13) Version updates
- The following versions are now available in the Stable channel:
- Version 1.24.11-gke.1000 is no longer available in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
(2023-R13) Version updates
- Version 1.25.8-gke.1000 is now the default version.
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.21.14-gke.18100
- 1.24.11-gke.1000
- 1.26.4-gke.500
- 1.26.4-gke.1400
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.20 to version 1.21.14-gke.18800 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.21.14-gke.18800 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
(2023-R13) Version updates
- Version 1.25.8-gke.1000 is now the default version in the Regular channel.
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.22.17-gke.8000
- 1.23.17-gke.2000
- 1.25.8-gke.500
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.11400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.25 to version 1.25.8-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
(2023-R13) Version updates
- Version 1.27.2-gke.1200 is now the default version in the Rapid channel.
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.11400
- 1.23.17-gke.5600
- 1.24.14-gke.1200
- 1.25.9-gke.2300
- 1.26.3-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.12700 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.6800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.1400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.10-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.26.5-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.26 to version 1.26.5-gke.1200 with this release.
The chat-bison@001 model has been updated to better follow instructions in the context field. For details, on how to create chat prompts for chat-bison@001, see Design chat prompts.
Cloud Asset Inventory support for Workflows is now publicly available. For details, see the Cloud Asset Inventory release note.
June 14, 2023
Anthos clusters on VMwareAnthos clusters on VMware 1.14.5-gke.41 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.14.5-gke.41 runs on Kubernetes 1.25.8-gke.1500.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.15, 1.14, and 1.13.
The component access service account key for an admin cluster using a private
registry can be updated in 1.14.5 and later. See
Rotating service account keys
for details.
The following issues are fixed in 1.14.5-gke.41:
- Fixed a known issue where the kind cluster downloads container images from docker.io. These container images are now preloaded in the kind cluster container image.
- Fixed a bug where disks may be out of order in the first boot, causing node bootstrap failure.
- Fixed a known issue where node ID verification failed to handle hostnames with dots.
- Fixed an issue where gcloud fails to update the platform when the
required-platform-versionis already the current platform version. - Fixed the Anthos Config Management
gcloudissue that the policy controller state might be falsely reported as pending. - Fixed continuously increasing memory usage of the logging agent
stackdriver-log-forwarder. - Fixed the wrong admin cluster resource link annotation key that can cause the cluster to be enrolled in the Anthos On-Prem API again by mistake.
- Fixed a known issue where some cluster nodes couldn't access the HA control plane when the underlying network performs ARP suppression.
- Fixed a
known issue
where
vsphere-csi-secretis not updated duringgkectl update credentials vspherefor admin cluster
The following vulnerabilities are fixed in 1.14.5-gke.41
High-severity container vulnerabilities:
Anthos clusters on VMware 1.13.9-gke.29 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.13.9-gke.29 runs on Kubernetes 1.24.11-gke.1200.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.15, 1.14, and 1.13.
The following issues are fixed in 1.13.9-gke.29:
- Fixed a known issue where the kind cluster downloads container images from docker.io. These container images are now preloaded in the kind cluster container image.
- Fixed the issue where
gkectlfailed to limit the time window forjournalctlcommands running on the cluster nodes when you take a cluster snapshot with the--log-sinceflag. - Fixed an issue where gcloud fails to update the platform when the
required-platform-versionis already the current platform version. - Fixed a known issue where nodes fail to register if the configured hostname contains a period.
- Fixed the wrong admin cluster resource link annotation key that can cause the cluster to be enrolled again by mistake.
The following high-severity container vulnerabilities are fixed in 1.13.9-gke.29:
hybrid v1.8.8
On June 14, 2023 we released an updated version of the Apigee hybrid software, v1.8.8.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.8.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 273561434 | Some projects were unable to run debug sessions.. |
| 279193831 | Envoy has been updated to v1.25.6.. |
| 279712107 | Added the ability to annotate apigee-ingressgateway-manager pods through overrides.yaml file. |
| 280544499 | Request headers were not seen in debug sessions. |
| 284488296 | Removed an unneeded Workload Identify on the Cassandra Schema Validation cron job. |
| Bug ID | Description |
|---|---|
| 281561243 | Security fix for apigee-diagnostics-collector, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerability: |
| 273797045 | Security fix for for apigee-diagnostics-collector apigee-synchronizer apigee-udca. This addresses the following vulnerability: |
| 273800345, 281572616 | Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, apigee-synchronizer, and apigee-udca. This addresses the following vulnerabilities: |
| 273801301 | Security fixes for apigee-mart-server and apigee-runtime. This addresses the following vulnerability: |
BigQuery now provides information about the fail-safe period. The fail-safe period offers an additional seven days of data storage after the time travel window, so that the data is available for emergency recovery. This feature is in preview.
The INFORMATION_SCHEMA views that show table storage metadata are now generally available (GA):
- Use the
TABLE_STORAGEview to get a snapshot of current storage usage for tables at the project level. - Use the
TABLE_STORAGE_BY_ORGANIZATIONview to get a snapshot of current storage usage for tables at the organization level.
BigLake Metastore is now generally available (GA). You can use BigLake Metastore to access and manage Iceberg table metadata from multiple sources.
IOC matching has been changed so that a domain match occurs only if the event timestamp lies within the active time range interval present in the threat intelligence feed. If a threat intelligence feed does not have an active time range interval, an IOC match is returned anytime the domain is identified in feed data. For information about IOC Domain matches, see View IOC matches.
The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.
- Microsoft AD FS (
ADFS) - Apache (
APACHE) - Linux Auditing System (AuditD) (
AUDITD) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - Azure Firewall (
AZURE_FIREWALL) - Zeek JSON (
BRO_JSON) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco VCS Expressway (
CISCO_VCS) - Corelight (
CORELIGHT) - CrowdStrike Detection Monitoring (
CS_DETECTS) - Digital Guardian DLP (
DIGITALGUARDIAN_DLP) - F5 BIGIP Access Policy Manager (
F5_BIGIP_APM) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - Fluentd Logs (
FLUENTD) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - Forescout NAC (
FORESCOUT_NAC) - FortiGate (
FORTINET_FIREWALL) - Apigee (
GCP_APIGEE_X) - Cloud SQL (
GCP_CLOUDSQL) - GitHub (
GITHUB) - GMAIL Logs (
GMAIL_LOGS) - Apache Hadoop (
HADOOP) - Imperva (
IMPERVA_WAF) - Kemp Load Balancer (
KEMP_LOADBALANCER) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Cloud Audit Logs (
N/A) - Firewall Rule Logging (
N/A) - Security Command Center Threat (
N/A) - Netskope (
NETSKOPE_ALERT) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Okta User Context (
OKTA_USER_CONTEXT) - 1Password (
ONEPASSWORD) - OSQuery (
OSQUERY_EDR) - OSSEC (
OSSEC) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Web Browser Isolation(
PROOFPOINT_WEB_BROWSER_ISOLATION) - Saviynt Enterprise Identity Cloud (
SAVIYNT_EIP) - SentinelOne EDR (
SENTINEL_EDR) - Sentinelone Alerts (
SENTINELONE_ALERT) - Tripwire (
TRIPWIRE_FIM) - Windows Defender ATP (
WINDOWS_DEFENDER_ATP) - Windows Event (
WINEVTLOG) - WordPress (
WORDPRESS_CMS) - Workspace Activities (
WORKSPACE_ACTIVITY) - ZScaler VPN (
ZSCALER_VPN)
For details about changes in each parser, see Supported default parsers.
Cloud Composer 2 is now available in Finland (europe-north1), Toronto (northamerica-northeast2), and Delhi (asia-south2).
Cloud Data Fusion version 6.9.1 is in Preview. This release is in parallel with the CDAP 6.9.1 release.
Features in Cloud Data Fusion 6.9.1:
Cloud Data Fusion supports using Source Control Management to manage pipeline versions through GitHub repositories. Source Control Management is available in Preview (CDAP-20228).
Data Catalog Asset Lineage Integration is in GA in versions 6.8.0 and later. In version 6.9.1, it supports the Multiple Database Tables source and the BigQuery Multi Table sink.
Cloud Data Fusion supports editing deployed pipelines (CDAP-19425).
Cloud Data Fusion supports Window Aggregation operations in Transformation Pushdown to reduce the pipeline execution time by performing SQL operations in BigQuery instead of Spark (CDAP-19628).
Cloud Data Fusion supports specifying filters in SQL in Wrangler and the pushdown of SQL filters in Wrangler to BigQuery. In the Wrangler transformation, added support for specifying preconditions in SQL, and added support for transformation pushdown for SQL preconditions. For more information, see Wrangler Filter Pushdown (CDAP-20454).
Cloud Data Fusion supports Dataproc driver node groups. To use Dataproc driver node groups, when you create the Dataproc cluster, configure the following properties:
yarn:yarn.nodemanager.resource.memory.enforced=falseyarn:yarn.nodemanager.admin-env.SPARK_HOME=$SPARK_HOME
For the Multiple Database Tables Batch Source, added field-level lineage support (CDAP-20440).
Cloud Data Fusion version 6.9.1 supports the Dataproc image 2.1 compute engine, which runs in Java11. If you change the Dataproc image to 2.1, the JDBC drivers that the database plugins use in those instances must be compatible with Java11 (CDAP-20543).
Cloud Data Fusion supports the following improvements and changes for real time pipelines with a single Pub/Sub streaming source and no Windower plugins:
- The Pub/Sub streaming source has built-in support—data is processed at least once.
- Enabling Spark checkpointing isn't required. Pub/Sub streaming source creates a Pub/Sub snapshot at the beginning of each batch and removes it at the end of each batch.
- The Pub/Sub Snapshot creation has a cost associated with it. For more information, see Pub/Sub pricing.
- The snapshot creations can be monitored using Cloud Audit logs.
For more information, see Read from a Pub/Sub streaming source (PLUGIN-1537).
Changes in Cloud Data Fusion 6.9.1:
Updated Cloud Data Fusion docker image dependencies to include fixes for security vulnerabilities.
Added the ability to configure Java options for a pipeline run by setting the
system.program.jvm.optsruntime argument (CDAP-20381).Replication pipelines generate logs for stats of events processed by source and target plugins at a fixed interval (CDAP-20140).
Streaming pipelines that use Spark checkpointing can use macros if the
cdap.streaming.allow.source.macrosruntime argument is set to true. Note that macro evaluation will only be performed for the first run in this case, then stored in the checkpoint. It will not be re-evaluated in later runs (CDAP-20455).Improved performance of replication pipelines by caching schema objects for data events (CDAP-20488).
Added a launch mode setting to the Dataproc provisioners. When set to Client mode, the program launcher will run in the Dataproc job itself, and not as a separate YARN application. This reduces start-up time and cluster resources required, but may cause failures if the launcher needs more memory, such as when there's an action plugin that loads data into memory (CDAP-20500).
Removed duplicate backend calls when a program reads from the secure store (CDAP-20504).
Added support to upgrade Pipeline Post-run Action (Pipeline Alerts) plugins during the pipeline upgrade process (CDAP-20567).
Added Lifecycle microservices endpoint to delete a streaming application state for Kafka Consumer Streaming and Google Cloud Pub/Sub Streaming sources (CDAP-20466).
Fixed in Cloud Data Fusion 6.9.1:
For SQL Server replication sources, fixed an issue on the Review assessment page, where SQL Server
DATETIMEandDATETIME2columns were shown as mapped toTIMESTAMPcolumns in BigQuery. This was a UI bug. The replication job mapped the data types to the BigQueryDATETIMEtype (CDAP-19389).For replication jobs, fixed an issue where retries for transient errors from BigQuery might have resulted in data inconsistency (CDAP-20276).
Fixed an issue where a replication job got stuck in an infinite retry when it failed to process a DDL operation (CDAP-20301).
When you duplicate a pipeline, Cloud Data Fusion appends
_copyto the pipeline name when it opens in the Pipeline Studio. In previous releases, Cloud Data Fusion appended_<v1, v2, v3>to the name (CDAP-20373).Fixed the pipeline stage validation API to return unevaluated macro values to prevent secure macros from being returned (CDAP-20430).
Fixed an issue that sometimes caused pipelines to fail when running pipelines on Dataproc with the following error:
Unsupported program type: Spark. The first time a pipeline that only contained actions ran on a newly created or upgraded instance, it succeeded. However, the next pipeline runs, which included sources or sinks, might have failed with this error (CDAP-20431).Fixed an issue where the flow control running count metric (
system.flowcontrol.running.count) might be stale if no new pipelines or replication jobs were started (CDAP-20458).Fixed an issue where executor resource settings are not honored when
app.pipeline.overwriteConfigis set (CDAP-20549).In the Oracle batch source, the Oracle
NUMBERdata type defined without precision and scale by default was mapped to Cloud Data Fusionstringdata type. If these fields were used by an Oracle Sink to insert into aNUMBERdata type field in the Oracle table, the pipeline failed due to incompatibility between string andNUMBERtype. Now, the Oracle Sink inserts thesestringtypes intoNUMBERfields in the Oracle table (PLUGIN-1481).For Oracle batch sources, fixed an issue that caused the pipeline to fail when there was a
TIMESTAMP WITH LOCAL TIME ZONEcolumn set toNULLABLEand the source had values that wereNULL(PLUGIN-1494) .Fixed an issue where pipelines that had a Database batch source and an Oracle sink that used a connection object (using SYSDBA) to connect to an Oracle database failed to establish a connection to the Oracle database. This was due to a package conflict between the Database batch source and the Oracle sink plugins (PLUGIN-1503).
Fixed an issue where pipelines failed when the output schema was overridden in certain source plugins. This was because the output schema didn't match the order of the fields from the query. This happened when the pipeline included any of the following batch sources:
Database
Oracle
MySQL
SQL Server
PostgreSQL
DB2
MariaDB
Netezza
Cloud SQL PostgreSQL
Cloud SQL MySQL
Teradata
Pipelines no longer fail when you override the output schema in these source plugins. Cloud Data Fusion uses the name of the field to match the schema of the field in the result set and the field in the output schema {PLUGIN-1512).
For BigQuery Pushdown, fixed an issue when BigQuery Pushdown was enabled for an existing dataset, the Location where the BigQuery Sink executed jobs was the location specified in the Pushdown configuration, not the BigQuery Dataset location. The configured Location should have only been used when creating resources. Now, if the dataset already exists, the Location for the existing dataset is used (PLUGIN-1513).
For the Database sink, fixed an issue where the pipeline didn't fail if there was an error writing data to the database. Now, if there is an error writing data to the database, the pipeline fails and no data is written to the database (PLUGIN-1514).
Fixed an issue that checks
GETpermission on a namespace which does not exist yet during the namespace creation flow (CDAP-18394).Fixed an issue where Dataproc continued running a job when it couldn't communicate with the Cloud Data Fusion instance if the replication job or pipeline was deleted in Cloud Data Fusion (CDAP-20216).
Fixed an issue that caused pipelines with triggers with runtime arguments to fail after the instance was upgraded to Cloud Data Fusion 6.8.0 and 6.9.0 (CDAP-20568).
Fixed an issue where arguments set by actions and pipeline triggers don't overwrite runtime arguments. You must add the following runtime argument:
system.skip.normal.macro.evaluation=true(CDAP-20597).Fixed an issue that caused the Pipeline Studio page to show an incorrect count of triggers (CDAP-20655).
Fixed an issue that caused the Trigger's Payload Config to be missing in the UI for an upgraded instance (CDAP-20660).
Fixed bug where initial offset was not considered in Kafka batch source (PLUGIN-1594).
With the introduction of editing deployed pipelines in Cloud Data Fusion 6.9.1, the behavior of some APIs have significantly changed. Due to these changes, some APIs are deprecated (CDAP-20030).
In Cloud Data Fusion 6.9.1, all datasets except FileSet and ExternalDataset are deprecated and will be removed in a future release. All the deprecated datasets use the Table dataset in some form, which only works for programs running with the native provisioner on very old Hadoop releases (CDAP-20667).
The subscription pricing mode for the discovery service is now generally available. This pricing mode offers predictable and consistent costs, regardless of your data growth. In subscription mode, you choose how much compute time (capacity) to reserve for profiling. There is no charge for bytes profiled in this pricing mode. For more information, see Discovery pricing.
Cloud Functions now supports customer-managed encryption keys for 2nd gen functions at the General Availability release level.
New Dataproc Serverless for Spark runtime versions:
- 1.1.19
- 2.0.27
- 2.1.6
Google Cloud VMware Engine now supports the provisioning of Single Node Private Clouds, configuration of Management Subnets (HCX and Service Subnets), as well as CRUD of Private Connections using the GCloud CLI and VMware Engine API. These features streamline your VMware Engine process flows by using higher degrees of automation.
Clusters with low or no utilization can be identified by Idle Cluster insights.
Looker 23.10 includes the following changes, features, and fixes.
Expected Looker (original) rollout start: Tuesday, June 20, 2023
Expected Looker (original) final deployment and download available: Wednesday, June 28, 2023
Expected Looker (Google Cloud core) deployment start: Friday, June 30, 2023
Expected Looker (Google Cloud core) deployment end: Friday, July 14, 2023
Until API 3.0 and 3.1 are disabled in Looker 23.12, the new Deny API 3.x requests Legacy feature toggle can be used to configure a Looker instance to reject API 3.x requests and log those requests to the Looker system log. This will cause API 3.x requests on that instance to fail, allowing administrators to verify that no remaining calls are made to API 3.0 and 3.1.
Liquid value and rendered_value now return YYYY-MM-DD style dates for date references.
YAML LookML projects, except for LookML dashboards, will now return an error, and all content that is based on YAML LookML projects will break.
The LookML generator will always generate LookML for new projects, derived tables, and aggregate tables.
When you are exporting data to, for example, a CSV file, a date field backed by a string column in the backend database will now serialize the same as a date field backed by a date column: YYYY-MM-DD.
Starting in Looker 23.10, SSO embed functionality, including SSO embed APIs and other SSO embed-specific features, is disabled on the Standard and Enterprise editions of Looker (Google Cloud core) instances.
The new URL for the Looker Marketplace CDN is https://static-a.cdn.looker.app/marketplace/ instead of https://marketplace-api.looker.com/. If your Looker instance configuration requires explicit access to the Marketplace CDN, use the new domain value. The content at both URLs is identical, but https://marketplace-api.looker.com/ is now deprecated.
The Looker deployment process is now asynchronous when it is triggered by the deploy webhook. The deploy webhook will no longer require deployment to complete prior to responding, speeding up the webhook response time. With this change, the deploy webhook response will no longer contain commit information.
Performance of Git pull operations has been improved by leveraging Looker's required shared file system mount, since Looker does not support clustered deployments without a shared file system.
By default, new LookML projects require data tests to pass: If your project has one or more test parameters, you must run the data tests and the data tests must pass before you can deploy the project to production.
The Looker-Power BI Connector is now generally available. This connector lets users explore modeled Looker data through the Power BI interface. A Looker admin must enable this feature in the BI Connectors Admin page.
The model_fieldname_suggestions API endpoint now supports fields with suggest_dimension defined. Previously these would return a 404 error.
A function has been added to ensure that required fields are added to pivot fields to address an ordinal error. Additionally, a new function ensures that there are no duplicate fields in the ORDER BY.
SQL format queries will now be supported by the create_query_task API.
PNG downloads of visualizations from embedded Explores, Looks, and dashboards can now use applied themes.
Custom filters now support the zipcode data type for the matches_filter function.
The new Get embed URL feature lets you automatically generate a private embedding URL for a dashboard, a Look, or an Explore. The embed URL can optionally include parameters, such as filter values, and apply an existing theme.
The new Embed Your Data Welcome Guide steps first-time embedding users through creating a private embed URL for a dashboard, applying a theme to an embedded dashboard, and links to a new codelab that demonstrates how to create an SSO embed URL using one of Looker's publicly available scripts.
Selecting dashboard filter values containing a backslash and another special character will now properly filter the data.
When grouping fields or creating custom measures in Explore, the "matches a user attribute" feature of the filters is fixed.
Previously, users were unable to right-click to drill down on a point of a line/area/scatter series that had been customized from a column/bar chart and been put on a cross filtered dashboard. This issue has been fixed.
The CTE order for derived tables that share a common ancestor is now as expected.
The New LookML Runtime will not generate symmetric aggregate SQL for measures that have a sql_distinct_key that references dimensions in different views. This is also true if a dimension with primary_key: yes references a dimension in a different view.
A bug has been fixed for Legacy BigQuery that was preventing the approximate_threshold value from being added to the query SQL.
Markdown files in LookML projects are no longer accessible to Embed users through the "View Document" URLs described on the Types of files in a LookML project documentation page.
Fixed time fields with a yesno timeframe now display their names as expected.
When BI Engine Optimization is enabled, filter_expression for custom measures is supported.
A bug has been fixed where previously a blank filter value would still bring in required_fields in the New LookML Runtime.
An issue with rendering JPGs via the Looker API has been fixed.
An error when trying to go fullscreen from a dashboard has been fixed.
An update to the GitLab Merge Request URL due to a new naming scheme from GitLab has fixed a 404 issue.
For email destinations, the delivery time zone set will be applied to the filename of the schedule sent.
In Looker 23.10, Looker rendering supports Chrome versions up to and including Chrome 113. Looker versions earlier than Looker 23.10 support up to Chrome version 109.
reCAPTCHA Enterprise Mobile SDK v18.2.1 is now available for iOS.
In this version, the internal error that occurred on iOS 11, 12, and 13 devices when calling execute() is fixed. For information about the issue, see internal error when calling execute().
June 13, 2023
Anthos Service Mesh1.17.3-asm.1 is now available for in-cluster Anthos Service Mesh.
You can now download 1.17.3-asm.1 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.17.3 subject to the list of supported features. Anthos Service Mesh 1.17.3-asm.1 uses Envoy v1.25.7.
1.16.5-asm.2 is now available for in-cluster Anthos Service Mesh.
You can now download 1.16.5-asm.2 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.16.5 subject to the list of supported features. Anthos Service Mesh 1.16.5-asm.2 uses Envoy v1.24.8.
1.15.7-asm.16 is now available for in-cluster Anthos Service Mesh.
You can now download 1.15.7-asm.16 for in-cluster Anthos Service Mesh. It includes the features of Istio 1.15.7 subject to the list of supported features. Anthos Service Mesh 1.15.7-asm.16 uses Envoy v1.23.7.
The following preview features are now generally available (GA):
Application Integration is now generally available (GA)
Application Integration is now generally available in all the supported Google Cloud locations.
Preview features such as Cloud Scheduler trigger, Error catcher trigger, JavaScript task, Return task, and Google-managed encryption keys are now moved to GA.
The following new features are added in this GA release:
Cloud Monitoring
Application Integration is integrated with Cloud Monitoring to provide visibility into the usage, performance, alerts, and the overall health of your integration resources.
For more information, see Monitor Application Integration resources.
Inline connection creation
You can now use the Connectors task in Application Integration to directly create a new connection in the Integration Connectors platform.
For more information, see Connectors task.
Integration designer changes
Several styling and user experience enhancements have been made to the integration designer layout and user interface. The new enhancements include a new variable pane that lets you create and manage all your integration variables in one place, a revamped designer toolbar and navigation bar design, and a refreshed Integration designer canvas.
For more information, see Integration designer.
Application Integration v2 REST API is available in preview.
For more information, see REST API reference (v2).
Known issues
- Application Integration fails to set up in a new Google Cloud project
- Integration designer screen compatibility issue
For more information, see Application Integration known issues.
On June 13, 2023 Blockchain Node Engine became generally available. The user interface and APIs are now publicly available to all customers.
You can now grant a predefined role that only lets you view and manage incidents. For more information, see Access control: Incidents.
The Available GPUs page contains additional instructions for using the gcloud CLI or curl to specify a GPU machine type.
Dataflow now supports Confidential VMs for Dataflow worker VMs. For more information, see Dataflow service options.
Migrate to Virtual Machines lets you set up throttling on the Migrate Connector to control the rate at which data is transferred from the Migrate Connector. Throttling ensures that the migration process distributes bandwidth evenly between the migration and any other tasks using the network. In this way, the migration can complete successfully without disrupting any other tasks.
Private Service Connect interfaces are available in Preview. Private Service Connect interfaces let service producers initiate connections to consumer VPC networks.
June 12, 2023
AlloyDB for PostgreSQLYou can increase your quotas by submitting a request in the Quotas page.
You can now manage the storage quota for clusters through the Quotas page.
The query execution graph is now generally available (GA). You can use the query execution graph to diagnose query performance issues, and to receive query performance insights.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigtable
2.23.3 (2023-06-08)
Bug Fixes
Dependencies
Python
Changes for google-cloud-bigtable
2.19.0 (2023-06-08)
Features
Bug Fixes
Documentation
You can now create log sinks with user-defined service accounts. For more information, see Configure log sinks with user-managed service accounts.
A weekly digest of client library updates from across the Cloud SDK.
The Trace list page has been replaced with the Trace explorer page, which contains a more responsive and interactive Trace details section. The new design delivers an improved user experience when traversing spans and when viewing span details. For more information, see Find and explore traces.
cos-dev-109-17691-0-0
| Kernel | Docker | Containerd | GPU Drivers |
| COS-6.1.33 | v23.0.3 | v1.7.2 | v470.182.03(default),v525.105.17 |
Updated containerd to 1.7.2.
Updated sosreport to v4.5.3.
Updated app-containers/runc to 1.1.7.
Updated app-emulation/kubernetes to 1.27.1.
Rollback pciutils from 3.10.0 back to 3.7.0.
Enabled KVM-based nested virtualization for the x86 architecture.
Updated net-misc/curl to v8.1.0-r1.
Updated sys-apps/diffutils to v3.10.
Updated net-dns/c-ares to v1.19.1.
Updated dev-libs/openssl to v3.0.9. This resolves CVE-2023-2650.
Updated dev-lang/go to 1.20.4. This fixes CVE-2023-24539 CVE-2023-24540, and CVE-2023-29400.
Fixed CVE-2023-24329 in dev-lang/python.
Fixed ncurses upgrade to 6.4p20220423. This resolves CVE-2023-29491.
cos-93-16623-402-27
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Updated dev-libs/openssl to v1.1.1u. This resolves CVE-2023-2650.
Updated net-misc/curl to v8.1.0-r1. This resolves CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, and CVE-2023-28322.
Fixed CVE-2022-4269 in the Linux kernel.
Fixed CVE-2022-4269 in the Linux kernel.
Fixed CVE-2022-4269 in the Linux kernel.
Fixed CVE-2023-2124 in the Linux kernel.
cos-97-16919-294-35
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.176 | v20.10.14 | v1.6.20 | v470.182.03(default),v525.105.17 |
Updated dev-libs/openssl to v1.1.1u. This resolves CVE-2023-2650.
Updated net-misc/curl to v8.1.0-r1. This resolves CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, and CVE-2023-28322.
Fixed CVE-2022-4269 in the Linux kernel.
Fixed CVE-2022-4269 in the Linux kernel.
Fixed CVE-2022-4269 in the Linux kernel.
Fixed CVE-2023-2124 in the Linux kernel.
cos-105-17412-101-24
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.109 | v23.0.3 | v1.7.0 | v470.182.03(default),v525.105.17 |
Updated dev-libs/openssl to v1.1.1u. This resolves CVE-2023-2650.
Fixed CVE-2023-24329 in dev-lang/python.
Updated net-misc/curl to v8.1.0-r1. This resolves CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, and CVE-2023-28322.
Fixed CVE-2023-2124 in the Linux kernel.
cos-101-17162-210-26
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Updated dev-libs/openssl to v1.1.1u. This resolves CVE-2023-2650.
Updated net-misc/curl to v8.1.0-r1. This resolves CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, and CVE-2023-28322.
Fixed CVE-2023-2124 in the Linux kernel.
Cloud Armor for regional HTTP(S) load balancers is now available in public preview. For more information, see the Security policy overview.
Dual-stack LoadBalancer Services are now available in Preview. Dual-stack LoadBalancer Services are supported on both GKE Standard and Autopilot dual-stack clusters. To learn more, see Single-stack and dual-stack Services.
You can now use deprecation insights to identify clusters on versions 1.21 to 1.24 that use Pod Security Policy, which is unsupported on GKE version 1.25 and later.
A weekly digest of client library updates from across the Cloud SDK.
Node.js
Changes for @google-cloud/pubsub
3.7.1 (2023-06-08)
Bug Fixes
IP address support for SAP HANA deployment automation
You can assign static IP addresses to your VM instances while automating the deployment of SAP HANA on Google Cloud using the following Terraform arguments:
vm_static_ip,worker_static_ips, andstandby_static_ipsrepresent the master, worker, and standby nodes in a scale-out system.primary_static_ipandsecondary_static_iprepresent the primary and secondary instances in a scale-up system.
These arguments are available when you use the Terraform module version 202306120959 or later, provided by Google Cloud.
For more information, see the deployment guide for your SAP HANA scenario.
New Finding attribute: userAgent
The userAgent attribute is added to the Access object, which is included in the Finding object of the Security Command Center API.
The userAgent attribute identifies the user agent of the caller that is associated with a Security Command Center finding.
For more information, see the Security Command Center API documentation for the Finding object.
Storage Transfer Service now offers Preview support for providing a Secret Manager secret when creating transfer jobs from AWS S3 or Azure storage.
Secret Manager provides strong encryption, role-based access control, and audit logging to protect your secrets.
For details, see the Secret Manager section of the following documents:
Cloud Monitoring for Storage Transfer Service is now Generally Available (GA). This integration allows you to monitor the number of objects and data being transferred and to compute transfer speeds. This GA launch also adds monitoring of errors and error codes.
See Monitor transfer jobs for details.
June 09, 2023
Apigee AnalyticsOn June 9, 2023 we released an updated version of Apigee X.
| Bug ID | Description |
|---|---|
| 286452898 | Previously, the Apigee Analytics topk query parameter, which returns the top k results for a query, always returned the results in descending order, even when the order parameter was ASC. This has been fixed: results are now sorted according to the order parameter before returning the top k entries. |
You can now search on fields of type bytes in UDM search. Chronicle uses base64 encoding for byte literals. Byte literals must be enclosed in double quotes prefixed with the letter b, as shown in the following examples:
network.dhcp.client_identifier = b"7Ixbub6A0KMvugAAAAA"
metadata.id = b"AAAAADg51kPYn7Ixbub6A0KMvugAAAAABQAAAAgAAAA="
An environment can now run two Airflow triggerers. This feature was previously available only in Highly Resilient environments.
The apache-airflow-providers-google package in images with Airflow 2.5.1 and 2.4.3 was upgraded to version 2023.6.6+composer. This version is based on the public version 10.1.1, with additional fixes to some operators and upgrades to many SDK package dependencies (such as protobuf). Notable changes include:
- Google Ads default API changed from version 12 to 13.
protobuf==4.22.5is included, this is the first Cloud Composer version with protobuf version 4.x.- In this version of the provider package, the deprecated
delegate_toparameter is removed from all GCP operators, hooks, and triggers, as well as from Firestore and Gsuite transfer operators that interact with GCS. Impersonation can be achieved by utilizing theimpersonation_chainparameter instead. Thedelegate_to paramremains available only in Gsuite and marketing platform hooks and operators that don't interact with Google Cloud.
For a full list of changes in the apache-airflow-providers-google, see the changelog from version 8.9.0 to 10.1.1 on the apache-airflow-providers-google page.
(Cloud Composer 2) Fixed an issue where it was not possible to delete a Cloud Composer environment if the environment's service account was already deleted.
The google-cloud-asset package is added to images with Airflow 2.5.1 and 2.4.3.
Cloud Composer 2.3.0 images are available:
- composer-2.3.0-airflow-2.5.1 (default)
- composer-2.3.0-airflow-2.4.3
Cloud Composer versions 2.0.16, 2.0.15, 1.18.12, and 1.18.11, have reached their end of full support period.
You can now create and then configure Serverless VPC Access connector for your function directly from the Create form in the Google Cloud console at the Preview release level.
Google Cloud Managed Service for Prometheus can now ingest exemplars attached to histogram metrics. Exemplars are commonly used to attach trace data to latency metrics, to help you find the cause of a sudden change in metric values. For information, see Use Prometheus exemplars.
A new version of Managed Service for Prometheus is now available. Version 0.7.0 of managed collection for Kubernetes has been released. Users who deploy managed collection using kubectl should reapply the manifests. Users who deploy the service using gcloud or the GKE UI are already upgraded on clusters running version 1.25 or newer. Self-deployed collection users should upgrade their binaries to use gke.gcr.io/prometheus-engine/prometheus:v2.35.0-gmp.5-gke.0.
For details about the changes included, see the release page on GitHub.
You can now create and then configure a Serverless VPC Access connector for your service or job directly from the Create form in the Google Cloud console. (Preview)
In both the GoogleSQL and PostgreSQL dialects, adds support for the IF NOT EXISTS clause in CREATE TABLE, CREATE INDEX, and ALTER TABLE ADD COLUMN, along with IF EXISTS for DROP TABLE and DROP INDEX.
Generally available: Hyperdisk Throughput provides cost-effective and throughput-oriented block storage with dynamically configurable capacity and throughput. Hyperdisk volumes are durable network storage devices that your VMs can access, similar to Persistent Disk. For more information, see About Hyperdisk.
Generally available: NVIDIA A100 80GB GPUs are now available in the following additional regions and zones:
- Iowa, North America:
us-central1-a
For more information about using GPUs on Compute Engine, see GPU platforms.
Confidential Space. Ports can now be opened for ingress network traffic when using Confidential Space image version 230600 and above.
New Autopilot clusters that run GKE version 1.25.5-gke.1000 and later automatically use Image streaming to pull eligible images.
In addition to the existing egress network policy GKE already supports, you can now control the egress traffic of your Pods by using a network policy that matches a fully-qualified domain name or a regular expression. FQDN Network Policy is now available in Preview for clusters in version 1.26.4-gke.500 and later, and 1.27.1-gke.400 and later. For more information, see Control Pod egress traffic using FQDN network policies.
HIPAA compliance for Generative AI on Vertex AI
Generative AI support on Vertex AI now supports HIPAA compliance. The coverage includes components of the Model Garden and Generative AI Studio.
To learn more about Vertex certifications, see Vertex AI Features and certifications.
June 08, 2023
Cloud BuildWhen you enable the Cloud Build API in a project, Cloud Build automatically creates a default service account to execute builds on your behalf. This Cloud Build service account previously had the logging.privateLogEntries.list IAM permission, which allowed builds to have access to list private logs by default. This permission has now been revoked from the Cloud Build service account to adhere to the security
principle of least privilege.
For instructions and more details, see the Cloud Build security bulletin.
Cloud Data Fusion version 6.8.3 is generally available (GA). This release is in parallel with the CDAP 6.8.3 release.
Cloud Data Fusion 6.8.3 supports the ability to configure Java options for a pipeline run by setting the system.program.jvm.opts runtime argument (CDAP-20381).
Cloud Data Fusion 6.8.3 supports upgrades in the Pipeline Post-run Action (Pipeline Alerts) plugins during the pipeline upgrade process (CDAP-20567).
Fixed in 6.8.3:
- Fixed an issue where the event publish feature did not work with RBAC-enabled instances (CDAP-20375).
- Fixed an issue where executor resource settings were not honored when
app.pipeline.overwriteConfigwas set (CDAP-20549). - Fixed an issue that caused pipelines with triggers with runtime arguments to fail after the instance was upgraded to Cloud Data Fusion 6.8.0 and later (CDAP-20568).
- Fixed an issue where arguments set by actions and pipeline triggers don't overwrite runtime arguments. You must add the following runtime argument:
system.skip.normal.macro.evaluation=true(CDAP-20597). - Fixed an issue that caused the Studio page to show an incorrect count of triggers (CDAP-20655).
- Fixed an issue that caused the Trigger's Payload Config to be missing in the UI for an upgraded instance (CDAP-20660).
- Fixed an issue in the BigQuery Sink where the absence of an ordering key caused an exception (PLUGIN-1582).
- Fixed an issue where initial offset was not considered in the Kafka Batch Source (PLUGIN-1594).
Dual-stack IPv6 support on Dedicated Interconnect is now generally available. This launch includes IPv6 support for both Cloud Router and Cloud Interconnect products.
New Dataproc Serverless for Spark runtime versions:
- 1.1.18
- 2.0.26
- 2.1.5
The PD CSI Driver will be automatically enabled on upgrades to 1.25, for clusters with the add-on disabled. There are no cost implications for enabling the driver, and it requests only a small amount of node resources. This upgrade enables gce-pd volumes to continue working on Kubernetes clusters version 1.25 and later. You can still disable the driver manually after upgrade. For more details, see Configuring add-ons.
Dynamic links in navigation buttons
The URL of a navigation button can be provided dynamically from a dimension value. Learn more.
Usage-based pricing for organization-level activations of Security Command Center
You can now use usage-based pricing instead of a fixed-price subscription to activate Security Command Center Premium tier at the organization level. The feature lets you activate Security Command Center at the organization level yourself in the Cloud console. Billing for organization-level activations of Security Command Center is based on the resource consumption in your organization and uses a usage-based pricing model.
For more information, see Overview of organization-level activation.
Security Command Center Cryptomining Protection Program
The Security Command Center Cryptomining Protection Program is launched to General Availability. The program offers financial protection up to $1 million USD to cover unauthorized Google Cloud compute expenses that are associated with undetected cryptocurrency mining attacks for Security Command Center Premium customers.
For more information, see Security Command Center Cryptomining Protection Program.
June 07, 2023
Access ApprovalAccess Approval supports Anthos Identity Service in the Preview stage.
Zendesk plugins version 1.2.0 is available in the Cloud Data Fusion Hub. The following changes are included in version 1.2.0:
- Zendesk Multi Objects Batch Source is generally available (GA).
- The Zendesk plugins support Connection Management.
Dataplane v2 for Cloud Interconnect is fully available for customers using Dedicated Interconnect or Partner Interconnect in the following regions:
- europe-west3 (Germany)
- southamerica-east1 (São Paulo)
All new VLAN attachments that you create in these regions are automatically provisioned on Dataplane v2. Existing VLAN attachments for these regions can be migrated to Dataplane v2. You can migrate existing attachments yourself by re-creating the attachments, or you can request and schedule an assisted migration. Contact Google Cloud Support for assistance.
For the list of all regions that are Dataplane v2-enabled, see the Locations table (Dedicated Interconnect) or Supported service providers (Partner Interconnect).
The global external HTTP(S) load balancer now supports a configurable client HTTP Keepalive Timeout. The client HTTP keepalive timeout represents the maximum amount of time that a TCP connection can be idle between the (downstream) client and the target HTTP/S proxy.
For details, see
This capability is available in Preview.
You can now import and export differential database backups. This can help you import and export data more frequently, reducing migration downtime.
Fine-grained access control is now available for PostgreSQL-dialect databases. For more information, see About fine-grained access control.
You can now view historical logs of maintenance events on your TPU in system event audit logs. For additional information see the maintenance events documentation.
The maximum event size that Datastream supports is now increased. The new limit is 10 MB when streaming data to BigQuery and 30 MB when streaming to Cloud Storage.
As of June 6, 2023, Google Cloud Deploy is ready to support HIPAA compliance.
(2023-R12) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane versions are now available:
- The following node versions are now available:
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.8-gke.1000 with this release.
Stable channel
- Version 1.25.8-gke.1000 is now the default version in the Stable channel.
- Version 1.21.14-gke.18100 is no longer available in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to version 1.21.14-gke.18800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.21.14-gke.18800 with this release.
Regular channel
- Version 1.24.13-gke.2500 is now available in the Regular channel.
- Version 1.24.12-gke.500 is no longer available in the Regular channel.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.12-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.12-gke.1000 with this release.
Rapid channel
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.8000
- 1.23.17-gke.2000
- 1.23.17-gke.3600
- 1.24.13-gke.2500
- 1.25.8-gke.1000
- 1.26.4-gke.500
- 1.26.4-gke.1400
- 1.27.1-gke.400
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.11400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
(2023-R12) Version updates
- The following control plane versions are now available:
- The following node versions are now available:
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.8-gke.1000 with this release.
(2023-R12) Version updates
- Version 1.25.8-gke.1000 is now the default version in the Stable channel.
- Version 1.21.14-gke.18100 is no longer available in the Stable channel.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.20 to version 1.21.14-gke.18800 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.21.14-gke.18800 with this release.
(2023-R12) Version updates
- Version 1.24.13-gke.2500 is now available in the Regular channel.
- Version 1.24.12-gke.500 is no longer available in the Regular channel.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.12-gke.1000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.12-gke.1000 with this release.
(2023-R12) Version updates
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.8000
- 1.23.17-gke.2000
- 1.23.17-gke.3600
- 1.24.13-gke.2500
- 1.25.8-gke.1000
- 1.26.4-gke.500
- 1.26.4-gke.1400
- 1.27.1-gke.400
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.11400 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.5600 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.14-gke.1200 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.25 to version 1.25.9-gke.2300 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.27 to version 1.27.2-gke.1200 with this release.
PaLM Text and Embeddings APIs, and Generative AI Studio
The Generative AI support on Vertex AI is now generally available (GA).
With this feature launch, you can leverage the PaLM API to generate
AI models that you can test, tune, and deploy in your AI-powered applications.
With the GA of these features, you will incur usage costs if you use the
text-bison and textembedding-gecko PaLM APIs. To learn about pricing, see
the Vertex AI pricing page.
Features and models in this release include:
- PaLM 2 for Text:
text-bison - Embedding for Text:
textembedding-gecko - Generative AI Studio for Language
Vertex AI Model Garden
The Vertex AI Model Garden is now generally available (GA). The Model Garden is a platform that helps you discover, test, customize, and deploy Vertex AI and select OSS models. These models range from tunable to task-specific - all available on the Model Garden page in the Google Cloud console.
To get started, see Explore AI models and APIs in Model Garden.
Vertex AI Codey APIs
The Vertex AI Codey APIs are now in Preview.
With the Codey API, code generation, code completion, and code chat APIs can be used from any Google Cloud project without allowlisting. The APIs can be accessed from the
us-central1 region. The Codey APIs can be used in the Generative AI studio or
programmatically in REST commands.
To get started, see the Code models overview.
June 06, 2023
Access TransparencyAccess Transparency supports Memorystore for Redis in the GA stage.
The Anthos Config Management SKU and Anthos Policy Controller SKU are end-of-sale. As of September 4, 2023, you must have an Anthos license to use Anthos Config Management. If you are using the Anthos Config Management SKU, migrate to an Anthos license by enabling the Anthos API on your project.
Security bulletin
A new vulnerability (CVE-2023-2878) has been discovered in the secrets-store-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. For more information, see the GCP-2023-009 security bulletin.
Security bulletin
A new vulnerability (CVE-2023-2878) has been discovered in the secrets-store-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. For more information, see the GCP-2023-009 security bulletin.
Security bulletin
A new vulnerability (CVE-2023-2878) has been discovered in the secrets-store-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. The severity of this Security Bulletin is None. For more information, see the GCP-2023-009 security bulletin.
The following changes are available in the Unified Data Model.
New fields were added to Entity, called risk_score and metric.
A new field was added to EntityMetadata, called
event_metadata.
The following new types were added to Entity:
EntityRiskMetricRiskDeltaMetric.Measure
The following new types were added to Event:
AttackDetailsExifInfoFileMetadataCodesignFileMetadataPEFileMetadataSignatureInfoPDFInfoSignatureInfoX509AttackDetails.TacticAttackDetails.TechniqueSecurityResult.AssociationSecurityResult.Association.AssociationAliasSecurityResult.SourceSecurityResult.ProviderMLVerdictSecurityResult.AnalystVerdictSecurityResult.Verdict
The following new enumerated types were added to Entity:
Metric.AggregateFunctionMetric.DimensionMetric.MetricNameRelation.EntityLabel
The following new enumerated types were added to Event:
ProcessTokenElevationTypeSecurityResult.VerdictResponseSecurityResult.Association.AssociationType
New field added to Relation, called entity_label.
New value added to EntityMetadata.EntityType, called
METRIC.
New fields added to Event.Metadata called log_type, base_labels, enrichment_labels.
New fields added to Noun, called security_result and
network.
New fields added to SecurityResult, called risk_score,
attack_details, first_discovered_time,
associations, campaigns, and verdicts.
New fields added to File, called pe_file,
tags, last_analysis_time, embedded_urls,
embedded_domains, embedded_ips,
exif_info, signature_info, pdf_info.
New field added to Process, called integrity_level_rid
and token_elevation_type.
New fields added to SignerInfo, called status,
valid_usage, cert_issuer.
The Resource.id field was deprecated. Use
resource.name or resource.product_object_id instead.
The following values were added to the EventTypes enumerated type:
DEVICE_FIRMWARE_UPDATEDEVICE_CONFIG_UPDATEDEVICE_PROGRAM_UPLOADDEVICE_PROGRAM_DOWNLOAD
The following additional values were added to the
ApplicationProtocol enumerated type:
CIPCOTPDNP3DICOMGOOSEIEC104MMSPTPSNMPSV
New values added to the Network.IpProtocol enumerated type, called ICMP and SCTP.
For a list of all fields in the Unified Data Model, and their descriptions, see the Unified Data Model field list.
Use folders and organizations in budgets: When you set up budgets for your Cloud Billing account, you can set the budget's scope to one or more folders or organizations that are linked to your account, in addition to the current options for specific projects and labels.
When you create a budget that applies to a folder or organization, the budget also covers future projects that you create in the folder or organization.
Learn about creating and modifying budgets for your Cloud Billing account.
For MIGs that have T2D machine series VMs, autoscaling based on CPU utilization doesn't work as expected. For more details, see Known issues.
A new vulnerability (CVE-2023-1872) has been discovered in the Linux kernel that can lead to a privilege escalation to root on the node. For more information, see the GCP-2023-008.
A new vulnerability (CVE-2023-2878) has been discovered in the secrets-store-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. On GKE, the severity is None. For more information, see the GCP-2023-009 security bulletin.
Access Transparency is now Generally Available for Memorystore for Redis.
Generally available: The Estimated cut-over time field is now generally available. This field gives an estimate of the time it takes to complete a cut-over job for a VM once the cut-over is triggered. This field is populated only for an active VM that has completed a few replication cycles.
We discovered a security vulnerability in the Storage Transfer Service agent container. We've fixed this issue with a container update that is more secure.
If you're running agents that were installed on or before February 17, 2023, you should follow the instructions in the Action required email sent to your account email address to update the container image.
Agents installed after February 17, 2023 do not need to be updated.
June 05, 2023
AlloyDB for PostgreSQLAlloyDB for PostgreSQL is now available in the following regions:
us-east5 (Columbus)us-south1 (Dallas)
For more information, see AlloyDB Locations.
This release includes the following Anthos attached clusters platform versions:
- 1.24.0-gke.4
- 1.25.0-gke.4
- 1.26.0-gke.2
This release fixes the following vulnerability:
You can now launch clusters with the following Kubernetes versions:
- 1.24.13-gke.500
- 1.25.8-gke.500
- 1.26.4-gke.2200
Security bulletin
A new vulnerability (CVE-2023-1872) has been discovered in the Linux kernel that can lead to a privilege escalation to root on the node. For more information, see the GCP-2023-008.
1.26
Fixed an issue where Kubernetes 1.26.2 incorrectly applied the default StorageClass to PersistentVolumeClaims with the deprecated annotation volume.beta.kubernetes.io/storage-class.
This release fixes the following vulnerability:
For information about the latest known issues, see Known issues for Anthos clusters on AWS.
You can now launch clusters with the following Kubernetes versions:
- 1.24.13-gke.500
- 1.25.8-gke.500
- 1.26.4-gke.2200
Security bulletin
A new vulnerability (CVE-2023-1872) has been discovered in the Linux kernel that can lead to a privilege escalation to root on the node. For more information, see the GCP-2023-008.
1.26
Fixed an issue where Kubernetes 1.26.2 incorrectly applied the default StorageClass to PersistentVolumeClaims with the deprecated annotation volume.beta.kubernetes.io/storage-class.
This release fixes the following vulnerability:
Known issues:
For information about the latest known issues, see Known issues for Anthos clusters on Azure.
Known issue
If you create a version 1.13.8 or version 1.14.4 admin cluster, or upgrade an admin cluster to version 1.13.8 or 1.14.4, the kind cluster pulls the following container images from docker.io:
docker.io/kindest/kindnetddocker.io/kindest/local-path-provisionerdocker.io/kindest/local-path-helper
If docker.io isn't accessible from your admin workstation, the admin cluster creation or upgrade fails to bring up the kind cluster.
This issue affects the following versions of Anthos clusters on VMware:
- 1.14.4
- 1.13.8
For more information, including a workaround, see kind cluster pulls container images from docker.io on the Known issues page.
Security bulletin
A new vulnerability (CVE-2023-1872) has been discovered in the Linux kernel that can lead to a privilege escalation to root on the node. For more information, see the GCP-2023-008.
v2.1.0
On June 5, 2023, we released version 2.1.0 of Apigee Adapter for Envoy.
The application_id claim was added to the /verifyApiKey response.
ANNOUNCEMENT
hybrid v1.9.3
On June 5, 2023 we released an updated version of the Apigee hybrid software, v1.9.3.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.9.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 284488296 | Removed an unneeded Workload Identify on the Cassandra Schema Validation cron job. |
| Bug ID | Description |
|---|---|
| 273800965 | Security fix for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerability: |
| 273800345, 281572616 | Security fixes for apigee-diagnostics-collector, apigee-mart-server, apigee-mint-task-scheduler, apigee-runtime, apigee-synchronizer, and apigee-udca. This addresses the following vulnerabilities: |
| 273801301 | Security fixes for apigee-mart-server and apigee-runtime. This addresses the following vulnerability: |
| 283826216 | Security fixes for apigee-ingressgateway. This addresses the following vulnerabilities: |
| 283826785 | Security fixes for istiod. This addresses the following vulnerabilities: |
| 281561243 | Security fix for apigee-diagnostics-collector, apigee-mint-task-scheduler, apigee-runtime, and apigee-synchronizer. This addresses the following vulnerability: |
Batch is available in the following regions:
asia-east2(Hong Kong)europe-central2(Warsaw)us-south1(Dallas)us-west2(Los Angeles)us-west3(Salt Lake City)us-west4(Las Vegas)
For more information, see Locations.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-bigquery
2.27.0 (2023-05-30)
Features
Bug Fixes
Dependencies
- Update dependency com.google.api.grpc:proto-google-cloud-bigqueryconnection-v1 to v2.20.0 (#2720) (4962cac)
- Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230506-2.0.0 (#2707) (4d2ec07)
- Update dependency com.google.apis:google-api-services-bigquery to v2-rev20230520-2.0.0 (#2723) (5c64797)
- Update dependency com.google.cloud:google-cloud-bigquerystorage-bom to v2.37.2 (#2726) (052c47a)
- Update dependency com.google.cloud:google-cloud-datacatalog-bom to v1.24.0 (#2721) (7c357fb)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.10.1 (#2713) (744e83a)
Python
Changes for google-cloud-bigquery
3.11.0 (2023-06-01)
Features
Bug Fixes
On June 5, 2023 Blockchain Node Engine released a limited GA version of the software. Access to the user interface and APIs is limited to specific customers until the full GA release.
Features supported in this release include:
- Blockchain Node Engine is a fully-managed service for dedicated blockchain nodes.
- Ethereum support:
- Execution and consensus clients
- Full and Archive nodes
- JSON-RPC and WebSocket endpoints.
- With a single operation, Blockchain Node Engine provisions a new node with the specified configuration (network, region, client, node type), bootstrap it from a known-good snapshot, sync it with the blockchain, and ensure its availability.
- Google Cloud Armor always enabled.
See:
Chronicle now links to a customer-supplied Google Cloud Project to integrate more closely with Google Cloud services, such as Cloud IAM, Cloud Monitoring, and Cloud Audit Logs. Customers can now use Cloud IAM and workforce identity federation to authenticate using their existing identity provider.
Chronicle provides an onboarding and migration portal, available via Cloud Console, where new customers are able to provision and configure a new Chronicle SIEM instance, and existing customers can bind their current Chronicle SIEM instance to Google Cloud services.
For more information, see the following documentation:
The following resource types are now publicly available through the Export APIs (ExportAssets, ListAssets, and BatchGetAssetsHistory), Feed API, and Search APIs (SearchAllResources, SearchAllIamPolicies).
A weekly digest of client library updates from across the Cloud SDK.
Node.js
Changes for @google-cloud/bigtable
4.6.1 (2023-05-30)
Bug Fixes
- Properly handle asynchronous read from stream (#1284) (55d86ba). This could result in silently dropped rows in a
createReadStream. The bug is active when theReadRowsstream would be piped into a consumer that would defer the processing of the rows until the next event loop run (i.e. use aTransformthat would defer the callback invocation viasetTimeout()).
Java
Changes for google-cloud-bigtable
2.23.2 (2023-05-30)
Documentation
- samples: Add bigtable filter snippet (#1762) (48a6ed0)
- samples: Remove client initialization as the snippets are not used standalone (#1768) (a6ac97c)
Dependencies
- Update dependency com.google.cloud:google-cloud-monitoring-bom to v3.19.0 (#1769) (956c851)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.10.1 (#1767) (901b88f)
- Update dependency com.google.truth.extensions:truth-proto-extension to v1.1.4 (#1770) (a94a522)
- Update doclet version to v1.9.0 (#1761) (a5d4215)
Use Geo-location objects in firewall policy rules to filter external IPv4 and external IPv6 traffic based on specific geographic locations or regions. This feature is available in General Availability.
Use Threat Intelligence for firewall policy rules to secure your network by allowing or blocking traffic based on threat intelligence data. This feature is available in General Availability.
You can now configure CMEK and a default storage location for individual folders, in addition to organizations. For more information, see Configure default settings for organizations and folders and Configure CMEK for Cloud Logging.
A weekly digest of client library updates from across the Cloud SDK.
Node.js
Changes for @google-cloud/logging
10.5.0 (2023-05-30)
Features
Java
Changes for google-cloud-logging
3.15.2 (2023-05-30)
Dependencies
A monthly digest of client library updates from across the Cloud SDK.
Go
Changes for spanner/admin/database/apiv1
1.46.0 (2023-05-12)
Features
- spanner/admin/database: Add support for UpdateDatabase in Cloud Spanner (#7917) (83870f5)
- spanner: Make leader aware routing default enabled for supported RPC requests. (#7912) (d0d3755)
Bug Fixes
- spanner: Update grpc to v1.55.0 (1147ce0)
Java
Changes for google-cloud-spanner
6.41.0 (2023-04-28)
Features
- Add TransactionExecutionOptions support to executor. (#2396) (8327f21)
- Leader Aware Routing (#2214) (9695ace)
- Make leak detection configurable for connections (#2405) (85213c8)
Dependencies
- Update dependency com.google.api.grpc:proto-google-cloud-spanner-executor-v1 to v1.4.0 (#2395) (02dc53c)
- Update dependency com.google.cloud:google-cloud-monitoring to v3.17.0 (#2406) (d46097f)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.8.0 (#2400) (b815cb8)
- Update dependency com.google.cloud:google-cloud-trace to v2.16.0 (#2407) (7993be2)
- Update dependency org.junit.vintage:junit-vintage-engine to v5.9.3 (#2401) (8aa7a1d)
6.42.0 (2023-05-15)
Features
- Add support for UpdateDatabase in Cloud Spanner (#2265) (2ea06e7)
- Add support for UpdateDatabase in Cloud Spanner (#2429) (09f20bd)
Bug Fixes
- Add error details for INTERNAL error (#2413) (ed62aa6)
- Use javax.annotation.Nonnull in executor framework (#2414) (afcc598)
Dependencies
- Update dependency com.google.cloud:google-cloud-monitoring to v3.18.0 (#2426) (05a45f8)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.9.0 (#2427) (42dbfe3)
- Update dependency com.google.cloud:google-cloud-trace to v2.17.0 (#2428) (6f7fee8)
- Update dependency org.graalvm.buildtools:junit-platform-native to v0.9.22 (#2423) (679bb36)
- Update dependency org.graalvm.buildtools:native-maven-plugin to v0.9.22 (#2424) (a72f4ff)
- Update dependency org.graalvm.sdk:graal-sdk to v22.3.2 (#2391) (c082a1f)
6.42.1 (2023-05-22)
Dependencies
6.42.2 (2023-05-30)
Dependencies
- Update dependency com.google.cloud:google-cloud-monitoring to v3.19.0 (#2466) (6de2cf6)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.10.1 (#2465) (0a89f49)
- Update dependency com.google.cloud:google-cloud-trace to v2.18.0 (#2467) (45609ed)
6.42.3 (2023-05-31)
Performance Improvements
Node.js
Changes for @google-cloud/spanner
6.9.0 (2023-04-26)
Features
6.10.0 (2023-05-17)
Features
- Add support for UpdateDatabase (#1802) (f4fbe71)
- Add support for UpdateDatabase in Cloud Spanner (#1848) (dd9d505)
Bug Fixes
6.10.1 (2023-05-30)
Bug Fixes
- Set database admin and instance as having handwritten layers (republish docs) (3e3e624)
Python
Changes for google-cloud-spanner
3.32.0 (2023-04-25)
Features
3.33.0 (2023-04-27)
Features
3.34.0 (2023-05-16)
Features
Bug Fixes
3.35.0 (2023-05-16)
Features
3.35.1 (2023-05-25)
Bug Fixes
Generally available: Accelerator-optimized (G2) machine types with attached NVIDIA® L4 GPUs are generally available in the following regions and zones:
- Singapore, APAC:
asia-southeast1-b - Netherlands, Europe:
europe-west4-a,b,c - Iowa, North America:
us-central1-a,b - South Carolina, North America:
us-east1-b,d - Virginia, North America:
us-east4-a - Oregon, North America:
us-west1-a,b
cos-105-17412-101-17
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.109 | v23.0.3 | v1.7.0 | v470.182.03(default),v525.105.17 |
Updated ncurses to v6.4p20220423. This resolves CVE-2023-29491.
cos-93-16623-402-22
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Updated ncurses to v6.4p20220423. This resolves CVE-2023-29491.
cos-97-16919-294-28
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.176 | v20.10.14 | v1.6.20 | v470.182.03(default),v525.105.17 |
Updated ncurses to v6.4p20220423. This resolves CVE-2023-29491.
cos-101-17162-210-21
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.15.107 | v20.10.24 | v1.6.18 | v470.182.03(default),v525.105.17 |
Updated ncurses to v6.4p20220423. This resolves CVE-2023-29491.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for dataflow/apiv1beta3
0.9.0 (2023-05-30)
Features
- dataflow: Update all direct dependencies (b340d03)
0.9.0 (2023-05-30)
Features
- dataflow: Update all direct dependencies (b340d03)
Enterprise Search: Specify domains for the widget
To use the widget externally, you must provide a list of domains where the widget appears.
If, in an earlier version, you created a widget with API key authentication, that widget might not be supported.
To ensure that the widget continues working, you must reconfigure it: Follow the instructions on Add the widget to a webpage to specify one or more domains for your widget and to generate a fresh snippet for the widget.
Enterprise Search: No API keys
Generated API keys are no longer used by the widget. You can enable Public Access instead.
Enterprise Search: Multi-turn search
Multi-turn search is available in allowlisted preview. Multi-turn search enables follow up questions in context. For information, see Search with multi-turn.
Enterprise Search: PPTX, DOCX, and TXT formats
Enterprise Search supports search over PPTX, DOCX, and TXT documents as well as HTML and PDF documents. Support for the PPTX, DOCX, and TXT formats is available in preview.
For general information about unstructured data, see Unstructured data.
Personalize
Like Enterprise Search and Infobot, Personalize is a component of Gen App Builder. With Personalize, you build a state-of-the-art recommendation engines based on your own data. The recommendation engine uses AI to suggest documents that are similar to the document that the user is currently viewing.
Personalize is available in preview.
For information, see Get started with Personalize.
Enterprise Search: Purge data
The addition of the Purge Data button on the Documents page makes it easier to delete data from a data store. For information, see Delete data from a data store.
Enterprise Search: Collect feedback from users
You have the option to collect feedback (thumbs up or thumbs down) about the quality of the search results provided through the widget. Users who don't like the results can also select, from a list, the reason for their dislike. Feedback collection is available in preview.
For information about feedback collection, see Configure widget feedback.
Enterprise Search: Schema editing
Schemas for structured data stores can be viewed and updated from within the Google Cloud console. Schema editing is available in preview.
For information about schema viewing and editing, see View the schema definition for structured data, Update a schema for structured data, and Schemas: auto-detecting versus providing your own.
Enterprise Search: HIPAA compliance
Enterprise Search is ready to support HIPAA compliance.
Enterprise Search: Analytics
On the analytics dashboard, you can compare metrics for two time periods. The analytics dashboard is available in preview.
For information, see View analytics.
Enterprise Search: Re-import after changing the indexable setting on a field
It is no longer necessary to re-import data after changing an indexable field setting. See Configure search attributes.
(2023-R11) Version updates
GKE cluster versions have been updated.
New versions available for upgrades and new clusters
The following Kubernetes versions are now available for new clusters and for opt-in control plane upgrades and node upgrades for existing clusters. For more information on versioning and upgrades, see GKE versioning and support and Upgrades.
No channel
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.22.17-gke.7500
- 1.22.17-gke.9400
- 1.23.17-gke.1700
- 1.24.10-gke.2300
- 1.25.7-gke.1000
- 1.25.9-gke.400
- 1.26.2-gke.1000
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.8-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.3-gke.1000 with this release.
Stable channel
- Version 1.24.12-gke.500 is now the default version in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.22.17-gke.7500
- 1.23.17-gke.1700
- 1.24.10-gke.2300
- 1.25.8-gke.500
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.25 to version 1.25.8-gke.1000 with this release.
Regular channel
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.22.17-gke.7500
- 1.23.17-gke.1700
- 1.24.11-gke.1000
- 1.26.2-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.26 to version 1.26.3-gke.1000 with this release.
Rapid channel
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.9400
- 1.23.17-gke.1700
- 1.24.13-gke.500
- 1.25.9-gke.400
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.24.13-gke.2500 with this release.
(2023-R11) Version updates
- The following control plane and node versions are now available:
- The following control plane versions are no longer available:
- 1.22.17-gke.7500
- 1.22.17-gke.9400
- 1.23.17-gke.1700
- 1.24.10-gke.2300
- 1.25.7-gke.1000
- 1.25.9-gke.400
- 1.26.2-gke.1000
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.23 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.24 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.25 to version 1.25.8-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled will be upgraded from version 1.26 to version 1.26.3-gke.1000 with this release.
(2023-R11) Version updates
- Version 1.24.12-gke.500 is now the default version in the Stable channel.
- The following versions are now available in the Stable channel:
- The following versions are no longer available in the Stable channel:
- 1.22.17-gke.7500
- 1.23.17-gke.1700
- 1.24.10-gke.2300
- 1.25.8-gke.500
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.23 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.24 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Stable channel will be upgraded from version 1.25 to version 1.25.8-gke.1000 with this release.
(2023-R11) Version updates
- The following versions are now available in the Regular channel:
- The following versions are no longer available in the Regular channel:
- 1.22.17-gke.7500
- 1.23.17-gke.1700
- 1.24.11-gke.1000
- 1.26.2-gke.1000
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.23 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.24 to version 1.24.12-gke.500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Regular channel will be upgraded from version 1.26 to version 1.26.3-gke.1000 with this release.
(2023-R11) Version updates
- The following versions are now available in the Rapid channel:
- The following versions are no longer available in the Rapid channel:
- 1.22.17-gke.9400
- 1.23.17-gke.1700
- 1.24.13-gke.500
- 1.25.9-gke.400
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.21 to version 1.22.17-gke.8000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.22 to version 1.23.17-gke.2000 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.23 to version 1.24.13-gke.2500 with this release.
- Control planes and nodes with auto-upgrade enabled in the Rapid channel will be upgraded from version 1.24 to version 1.24.13-gke.2500 with this release.
A weekly digest of client library updates from across the Cloud SDK.
Java
Changes for google-cloud-pubsub
1.123.13 (2023-05-30)
Dependencies
- Update dependency com.google.cloud:google-cloud-bigquery to v2.26.0 (#1582) (a7c09b7)
- Update dependency com.google.cloud:google-cloud-bigquery to v2.26.1 (#1585) (e2c37bf)
- Update dependency com.google.cloud:google-cloud-core to v2.18.1 (#1591) (1637f0d)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.10.0 (#1592) (a6be7b7)
- Update dependency com.google.cloud:google-cloud-shared-dependencies to v3.10.1 (#1594) (52263ce)
- Update dependency org.xerial.snappy:snappy-java to v1.1.10.0 (#1590) (338f31f)
Google Cloud's Agent for SAP version 2.0
Version 2.0 of Google Cloud's Agent for SAP is generally available (GA). This version introduces the opt-in feature of collecting SAP HANA monitoring metrics, making Google Cloud's Agent for SAP version 2.0 the successor to Google Cloud's monitoring agent for SAP HANA.
For more information, see What's new with Google Cloud's Agent for SAP.
Google Cloud's monitoring agent for SAP HANA is deprecated, and is replaced by the SAP HANA monitoring metrics collection feature of version 2.0 of Google Cloud's Agent for SAP. For upgrade instructions, see Google Cloud's Agent for SAP operations guide.
Support for the monitoring agent for SAP HANA ends on May 31, 2024.
A weekly digest of client library updates from across the Cloud SDK.
Go
Changes for secretmanager/apiv1
1.11.0 (2023-05-30)
Features
- secretmanager: Update all direct dependencies (b340d03)
June 04, 2023
Virtual Private CloudSupport for IPv6 static routes with the following next hops is available in Preview:
next-hop-gatewaynext-hop-instance
June 02, 2023
Access TransparencyAccess Transparency supports Anthos Identity Service in the Preview stage.
The following supported default parsers have changed. Each is listed by product name and ingestion label, if applicable.
- Aruba (
ARUBA_WIRELESS) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Cato Networks (
CATO_NETWORKS) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco PIX Firewall (
CISCO_PIX_FIREWALL) - Dope Security SWG (
DOPE_SWG) - F5 BIGIP LTM (
F5_BIGIP_LTM) - Falco IDS (
FALCO_IDS) - Fidelis Network (
FIDELIS_NETWORK) - ForgeRock OpenAM (
OPENAM) - FortiGate (
FORTINET_FIREWALL) - FortiMail Email Security (
FORTINET_FORTIMAIL) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GMAIL Logs (
GMAIL_LOGS) - IBM Safenet (
IBM_SAFENET) - IBM Security Access Manager (
IBM_SAM) - IBM Security QRadar SIEM (
IBM_QRADAR) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Mongo Database (
MONGO_DB) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Pulse Secure (
PULSE_SECURE_VPN) - Security Command Center Threat (
N/A) - Sentinelone Alerts (
SENTINELONE_ALERT) - SentinelOne EDR (
SENTINEL_EDR) - ServiceNow CMDB (
SERVICENOW_CMDB) - SonicWall (
SONIC_FIREWALL) - Strong Swan VPN (
STRONGSWAN_VPN) - ThreatLocker Platform (
THREATLOCKER) - VMware vRealize Suite (
VMWARE_VREALIZE) - VPC Flow Logs (
GCP_VPC_FLOW) - WatchGuard (
WATCHGUARD) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Workspace Activities (
WORKSPACE_ACTIVITY)
For details about changes in each parser, see Supported default parsers.
The SAP Ariba Batch Source plugin is generally available (GA). You can connect your data pipeline to an SAP Ariba Source and a BigQuery Sink with this plugin in Cloud Data Fusion versions 6.5.1 and later.
The SAP SuccessFactors Batch Source plugin is GA. You can connect your data pipeline to an SAP SuccessFactors Source and a BigQuery Sink with this plugin in Cloud Data Fusion versions 6.5.1 and later.
The rollout of the following minor versions, extension versions, and plugin versions is currently underway:
Minor versions
- 10.22 is upgraded to 10.23.
- 11.17 is upgraded to 11.19.
- 12.12 is upgraded to 12.14.
- 13.8 is upgraded to 13.10.
- 14.5 is upgraded to 14.7.
Extension and plugin versions
- pg_cron is upgraded from 1.4.1 to 1.5.
- pg_partman is upgraded from 4.7.0 to 4.7.3.
- postgresql-hll is upgraded from 2.16 to 2.17.
- pg_repack is upgraded from 1.4.7 to 1.4.8.
- wal2json is upgraded from 2.4 to 2.5.
- pg_hint_plan is upgraded, as follows:
- from 1.3.7 to 1.3.8 (for PostgreSQL versions 11-13)
- from 1.4.0 to 1.4.1 (for PostgreSQL version 14)
- from 1.4.0 to 1.5.0 (for PostgreSQL version 15)
If you use a maintenance window, then the updates to the minor, extension, and plugin versions happen according to the timeframe that you set in the window. Otherwise, the updates occur within the next few weeks.
The new maintenance version is [PostgreSQL version].R20230530.01_00. To learn how to check your maintenance version, see Self service maintenance. To find your maintenance window or to manage maintenance updates, see Find and set maintenance windows.
A vulnerability was recently discovered in Cloud SQL for SQL Server that allowed customer administrator accounts to create triggers in the tempdb database and use those to gain sysadmin privileges in the instance. The sysadmin privileges would give the attacker access to system databases and partial access to the machine running that SQL Server instance.
Google Cloud resolved the issue by patching the security vulnerability by March 1, 2023. Google Cloud didn't find any compromised customer instances.
For instructions and more details, see the Cloud SQL security bulletin.
New Dataproc Serverless for Spark runtime versions:
- 1.1.17
- 2.0.25
- 2.1.4
Upgrade Cloud Storage connector to 2.2.14 version in Dataproc Serverless for Spark runtimes.
Eventarc support for creating triggers for direct Transcoder API events is available in Preview.
Support for joining a Windows Compute Engine VM automatically to a Managed Microsoft AD domain is generally available with the following updates:
- Added a new
managed-ad-forceflag to reuse an existing computer account. - Improved the existing
managed-ad-ou-nameflag to specify the path of the custom OU.
For more information, see Metadata.
Using the automated domain join feature, you can also join GKE Windows Server nodes automatically to a Managed Microsoft AD domain.
The Google Cloud console has been updated to change how you open Security Command Center pages. Previously, you selected pages using tabs on the main page. Now you select pages from the slide-out menu on the left side of the console. To show the menu, hold your pointer over the icons on the left side of the console.
For an overview of the pages, see Using Security Command Center in the Google Cloud console.
June 01, 2023
AlloyDB for PostgreSQLContinuous backup and recovery is generally available (GA).
Anthos clusters on VMware 1.15.1-gke.40 is now available. To upgrade, see Upgrading Anthos clusters on VMware. Anthos clusters on VMware 1.15.1-gke.40 runs on Kubernetes 1.26.2-gke.1001.
The supported versions offering the latest patches and updates for security vulnerabilities, exposures, and issues impacting Anthos clusters on VMware are 1.15, 1.14, and 1.13.
Fixed a known issue where node ID verification failed to handle hostnames with dots.
Fixed continuous increase of logging agent memory.
Fixed an issue where
cluster-api-controllersin a high-availability admin cluster had no Pod anti-affinity. This could allow the threeclusterapi-controllersPods not to be scheduled on different control-plane nodes.Fixed the wrong admin cluster resource link annotation key that can cause the cluster to be enrolled again by mistake.
Fixed a known issue where node pool creation failed because of duplicated VM-Host affinity rules.
The preflight check for StorageClass parameter validations now throws a warning instead of a failure on ignored parameters after CSI Migration. StorageClass parameter
diskformat=thinis now allowed and does not generate a warning.Fixed an issue where
gkectl repair admin-mastermight fail withFailed to repair: failed to delete the admin master node object and reboot the admin master VM.Fixed a race condition where some cluster nodes couldn't access the high-availability control plane when the underlying network performed ARP suppression.
Fixed a false error message for
gkectl preparewhen using a high-availability admin cluster.Fixed an issue where during user cluster update,
DeprecatedKubeceptionalways shows up in the diff.Fixed an issue where there were leftover Pods with failed status due to
Predicate NodeAffinity failedduring node re-creation.
Fixed the following vulnerabilities:
High-severity container vulnerabilities:
Container-optimized OS vulnerabilities:
Release 1.13.8
Anthos clusters on bare metal 1.13.8 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.13.8 runs on Kubernetes 1.24.
Fixes:
Fixed an issue that prevented Anthos clusters on bare metal from restoring a high-availability quorum for nodes that use
/var/lib/etcdas a mountpoint.Fixed an upgrade race condition between a node and the CNI, which could trigger two worker nodes to upgrade simultaneously.
The following container image security vulnerabilities have been fixed:
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
For Node.js runtimes version 18 and version 20 (preview), you can use the Pnpm package manager to configure dependencies for Node.js runtimes. Learn how to configure your runtime.
You can use the Pnpm package manager to configure dependencies for Node.js runtimes. Learn how to configure your runtime.
You can use the Pnpm package manager to configure dependencies for Node.js runtimes. Learn how to configure your application.
Updated content to reflect the new Alert view and Alert list. The following changes have been made to Alert view:
- New Overview and Alert History tabs. The Overview section provides a snapshot of important alert information. This is separate from the History tab to clearly differentiate between alert investigation and audit area.
- Detection widget now has a view other alerts from this rule button to get fast access to more alerts that came from this rule. Users can pivot to other alerts from this rule.
- Updated information on how to close an alert and change alert status.
- Updated information on how to adjust the time range.
- Updated information on how to apply single and multiple filters.
The following changes have been made to Alert list:
- Expanded columns to include Risk Score and Tags. This helps users to focus on and prioritize high-risk and critical security findings.
- Ingestion Time and Last Modified were also added to Alert List.
- Users can now customize columns in the Alert list, add or remove columns from the table.
- Expanded filters to include OR and AND operators to allow more complex filtering.
- Updated information on how to refresh Alert List.
These changes are documented in Investigate an alert and View Alerts and IOCs.
You can use the Pnpm package manager to configure dependencies for Node.js runtimes. Learn how to configure your runtime.
New sub-minor versions of Dataproc images:
- 2.0.66-debian10, 2.0.66-rocky8, 2.0.66-ubuntu18
- 2.1.14-debian11, 2.1.14-rocky8, 2.1.14-ubuntu20
Upgrade Cloud Storage connector version to 2.2.14 for 2.0 and 2.1 images
Backport HIVE-22891, HIVE-21660, HIVE-21915 to 2.0 images.
Backport HIVE-22891, HIVE-21660, HIVE-25520, HIVE-25521 to 2.1 images.
The price of an active delivery pipeline is reduced. Also, single-target delivery pipelines no longer incur a charge. Underlying service charges continue to apply. See the Google Cloud Deploy pricing page for details.
Agones on GKE users will get recommendations and insights if they did not install the Agones controller on dedicated nodes.
Preview stage support for the following integration:
Vertex Prediction
You can now specify a multi-region BigQuery table as the input or output to a batch prediction request.
May 31, 2023
Anthos clusters on bare metalRelease 1.15.1
Anthos clusters on bare metal 1.15.1 is now available for download. To upgrade, see Upgrading Anthos on bare metal. Anthos clusters on bare metal 1.15.1 runs on Kubernetes 1.26.
Functionality changes:
Updated the cluster snapshot capability so that information can be captured for the target cluster even when the cluster custom resource is missing or unavailable.
Improved
bmctlerror reporting for failures during the creation of a bootstrap cluster.Added support for using the
baremetal.cluster.gke.io/maintenance-mode-deadline-secondscluster annotation to specify the maximum node draining duration, in seconds. By default, a 20-minute (1200 seconds) timeout is enforced. When the timeout elapses, all pods are stopped and the node is put into maintenance mode. For example to change the timeout to 10 minutes, add the annotationbaremetal.cluster.gke.io/maintenance-mode-deadline-seconds: "600"to your cluster.Added
node_pool_nameto theanthos_baremetal_node_os_countmetric.
Fixes:
Fixed an issue that caused the
bmctl restorecommand to stop responding for clusters with manually configured load balancers.Fixed an issue that caused health checks to report failure when they find a Pod with a status of
TaintTolerationeven when the replicaset for the Pod has sufficient Pods running.Fixed an issue that prevented Anthos clusters on bare metal from restoring a high-availability quorum for nodes that use
/var/lib/etcdas a mountpoint.Fixed an issue that caused conflicts with third-party Ansible automation.
Fixed an issue where invalid kubelet image pull settings, such as negative values, resulted in update job failures. Unchecked job failures generate an excessive accumulation of kubelet configuration backup files.
Fixed a cluster upgrade issue that prevented some control plane nodes from rejoining a cluster configured for high availability.
The following container image security vulnerabilities have been fixed:
- CVE-2018-1099
- CVE-2019-19906
- CVE-2020-8032
- CVE-2021-3468
- CVE-2021-43784
- CVE-2022-2097
- CVE-2022-2196
- CVE-2022-3424
- CVE-2022-3707
- CVE-2022-4129
- CVE-2022-4304
- CVE-2022-4379
- CVE-2022-4382
- CVE-2022-4450
- CVE-2022-4904
- CVE-2022-24407
- CVE-2022-29162
- CVE-2022-41723
- CVE-2022-41725
- CVE-2023-0045
- CVE-2023-0215
- CVE-2023-0286
- CVE-2023-0458
- CVE-2023-0461
- CVE-2023-1073
- CVE-2023-1074
- CVE-2023-1076
- CVE-2023-1077
- CVE-2023-1078
- CVE-2023-1079
- CVE-2023-1118
- CVE-2023-1281
- CVE-2023-1513
- CVE-2023-1611
- CVE-2023-1670
- CVE-2023-1829
- CVE-2023-1855
- CVE-2023-1872
- CVE-2023-1989
- CVE-2023-1990
- CVE-2023-1998
- CVE-2023-2162
- CVE-2023-2194
- CVE-2023-21102
- CVE-2023-22998
- CVE-2023-23004
- CVE-2023-23559
- CVE-2023-25012
- CVE-2023-26545
- CVE-2023-27487
- CVE-2023-27488
- CVE-2023-27491
- CVE-2023-27492
- CVE-2023-27493
- CVE-2023-27496
- CVE-2023-28328
- CVE-2023-28466
- CVE-2023-28484
- CVE-2023-29469
- CVE-2023-30456
- CVE-2023-30772
- CVE-2023-32269
Known issues:
For information about the latest known issues, see Anthos clusters on bare metal known issues in the Troubleshooting section.
A release was made. Updates may include general performance improvements, bug fixes, and updates to the API reference documentation.
Cross-Cloud Interconnect is now generally available. Cross-Cloud Interconnect is a new variant of Cloud Interconnect that helps you establish high-bandwidth dedicated connectivity between Google Cloud and another cloud service provider.
When you buy Cross-Cloud Interconnect, Google provisions a dedicated physical connection between the Google network and that of another cloud service provider. You can use this connection to peer your Google Virtual Private Cloud (VPC) network with your network that's hosted by a supported cloud service provider. Supported providers include the following:
- Amazon Web Services (AWS)
- Microsoft Azure
- Oracle Cloud Infrastructure (OCI)
- Alibaba Cloud
For more information about the benefits and limitations of Cross-Cloud Interconnect, see the Cross-Cloud Interconnect overview.
Cloud Logging no longer creates a dedicated service account for each log sink. Instead, Logging reuses an existing service account when one is available for the resource type. Logging creates a service account when none are available. For more information, see Set destination permissions.
Preview: In a managed instance group (MIG), you can set metadata and labels for all VMs in the group without the need to create a new instance template. For more information, see Override instance template properties with an all-instances configuration.
The image import tool now supports importing CentOS Stream 9 and CentOS Stream 8 images to Google Cloud.
Dataproc Metastore gRPC endpoints are generally available (GA).
Metadata federation support for BigQuery and BigLake is generally available (GA).
Cross-Cloud Interconnect is now generally available. You can use a Cross-Cloud Interconnect connection to peer your Google Virtual Private Cloud (VPC) network with your network that's hosted by a supported cloud service provider. You can also use Cross-Cloud Interconnect VLAN attachments as part of a site-to-site data transfer strategy.
For example, after you configure a VLAN attachment for your Cross-Cloud Interconnect connection, you can create a Network Connectivity Center spoke to represent the attachment. If the spoke has site-to-site data transfer enabled, you can then transfer data between your remote cloud network and your other external sites. Other external sites can include your on-premises network or your network in other clouds.
For information about the cloud service providers that Cross-Cloud Interconnect supports, see the Cross-Cloud Interconnect overview. For information about site-to-site data transfer, see the Site-to-site data transfer overview.
Site-to-site data transfer is supported only in certain locations.
May 30, 2023
Apigee UIOn May, 30, 2023, we released an updated version of the Apigee UI.
The following labels in the Advanced API Security abuse detection view have been changed:
- Detection type has been changed to Detection rules.
- Suspected bot traffic has been changed to Detected traffic.
- Percent bot traffic has been changed to % of detected traffic.
- Bot count has been changed to Detected IP address count.
- Top API key has been changed to: Top app key.
- Bot reason has been changed to Detected rules.
- Total calls made has been changed to Detected traffic.
- First detection time has been changed to First event detected.
- Last detection time has been changed to Last event detected.
The advanced traffic management using flexible pattern matching capability with Global External HTTP(S) Load Balancer is now Generally Available.
Starting July 2023, the new composer.environments.executeAirflowCommand permission will be required to run Airflow CLI commands through the gcloud composer environments run command:
The
composer.userandcomposer.environmentAndStorageObjectViewerroles do not have this permission and will not be permitted to run Airflow CLI commands starting July 2023.This permission is already available in IAM and you can assign it in advance.
This permission is already added to the
composer.admincomposer.environmentAndStorageObjectAdminroles.This change applies only to Cloud Composer 2 environments. It will still be possible to run Airflow CLI commands on Cloud Composer 1 environments without this permission.
(Cloud Composer 2) The number of web server workers is now set dynamically based on available web server CPU and memory. This change improves Airflow web server performance and scalability by allowing it to handle more users.
These workers are internal to the gunicorn web server and are not related to workers that run tasks.
The new value is applied to the
[webserver]workersAirflow configuration option when you change the environment's configuration. To use a different value, override this Airflow configuration option.The number of web server workers is clamped between 2 and 12 workers and is calculated as the minimum of
(web_server_CPU * 2) + 1andweb_server_memory * 1.1.
(Cloud Composer 2) You can now use custom certificates when installing packages from your private repository.
(Cloud Composer 2) The deprecated [core]non_pooled_task_slot_count Airflow configuration option is replaced with the [core]default_pool_task_slot_count configuration option in the default Airflow configuration. Make sure to update your custom Airflow configuration overrides to use the new option instead of the deprecated one.
An improved error message is now displayed when a subnetwork with unsupported IPv4 ranges is used to create an environment in a shared VPC configuration.
Cloud Composer 2.2.1 images are available:
- composer-2.2.1-airflow-2.5.1 (default)
- composer-2.2.1-airflow-2.4.3
Cloud Composer versions 2.0.14, 2.0.13, 1.18.10, and 1.18.9, have reached their end of full support period.
Pub/Sub notifications containing FHIR data is generally available (GA).
Using the notificationConfig object on a FHIR store is deprecated. Use the notificationConfigs object instead.
The global external HTTP(S) load balancer now supports advanced traffic management using flexible pattern matching. This allows you to use wildcards anywhere in your path matcher. You can use this to customize origin routing for different types of traffic, request and response behaviors, and caching policies. In addition, you can now use results from your pattern matching to rewrite the path that is sent to the origin.
For details, see URL maps overview: Wildcards and pattern matching operators in path templates for route rules.
This capability is available in General availability.
Cloud NAT support for Standard Tier egress is available in Preview.
Config Controller now uses the following versions of its included products:
- Config Connector v1.104.0, release notes
cos-97-16919-294-27
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.176 | v20.10.14 | v1.6.20 | v470.182.03(default),v525.105.17 |
Fixed CVE-2023-28842 in docker.
cos-93-16623-402-21
| Kernel | Docker | Containerd | GPU Drivers |
| COS-5.10.177 | v20.10.14 | v1.5.18 | v450.236.01(default),v470.182.03(R470),v525.105.17 |
Fixed CVE-2023-28842 in docker.
Password policies are generally available (GA).
May 29, 2023
Cloud BigtableA weekly digest of client library updates from across the Cloud SDK.
A weekly digest of client library updates from across the Cloud SDK.
Node.js
Changes for @google-cloud/pubsub
3.7.0 (2023-05-26)
Features
Go
Changes for pubsub/apiv1
1.31.0 (2023-05-24)
Features
Bug Fixes
Python
Changes for google-cloud-pubsub
2.17.1 (2023-05-23)
Documentation
reCAPTCHA Enterprise Mobile SDK v18.2.1 is now available for Android.
This version fixed the issue that caused Failed to parse the message or Protocol message contained an invalid tag (zero) error. For more information about the issue, see unhandled exception in Android SDK 18.2.0.

