Welcome to issue #478 November 24th, 2025

News

Gemini Official Blog

Announcing Nano Banana Pro for every builder and business - Today, we announced Nano Banana Pro (Gemini 3 Pro Image). Nano Banana Pro excels in visual design, world knowledge, and text generation. It’s available on Vertex AI, Google Workspace, and Gemini Enterprise.

Infrastructure Official Blog

A new Google Cloud region is coming to Türkiye as part of $2 billion investment - When open, the new Google Cloud region in Türkiye will help meet growing demand for cloud services and AI-driven innovation in the country and EMEA.

Infrastructure Networking Official Blog

Introducing Dhivaru and two new connectivity hubs - Dhivaru: Google's new Trans-Indian Ocean subsea cable and connectivity hubs link Maldives, Christmas Island, and Oman, boosting digital resilience.

Gemini Official Blog

Building with Gemini in the newest Vertex AI Studio - Today, we’re sharing new ways Vertex AI Studio – Google’s developer console for production-ready AI – will help teams turn ideas into scalable, production gen AI apps. We've introduced powerful new tools that directly address developer needs for efficiency and collaboration.

BigQuery Data Analytics Official Blog

Expanding BigQuery Data Transfer Service with new connectors, features, and more - Learn about recent enhancements to the BigQuery Data Transfer Service connector ecosystem, security and compliance features, and the user experience.

AI BigQuery Data Analytics Official Blog

BigQuery AI: The convergence of data and AI is here - BigQuery AI, brings together BigQuery’s built-in ML capabilities, generative AI functions, vector search, intelligent agents, and agent tools.

Gemini CLI Looker Official Blog

Looker and Looker Conversational Analytics extensions available in the Gemini CLI - Looker and Looker Conversational Analytics extensions are available in the Gemini CLI, letting you interact with your data from the command line.

Cloud SQL Databases Official Blog

Announcing Cloud SQL free trial instances: Experience the power of a fully managed database - Announcing a new, 30-day Cloud SQL free trial instance program to test enterprise-grade features for MySQL and PostgreSQL, with no commitment.

ADK Data Analytics Official Blog

From interaction to insight: Announcing BigQuery Agent Analytics for the Google ADK - The new BigQuery Agent Analytics ADK plugin exports agent interaction data directly into BigQuery to capture, analyze, and visualize agent metrics.

BigLake Data Analytics Official Blog Streaming

Iceberg REST Catalog now supported in BigLake metastore (GA) for open data interoperability - With support for the Iceberg REST Catalog in BigLake metastore, users can query data using their engine of choice as part of a opne data lakehouse.

AI GCP Certification Official Blog

Production-Ready AI with Google Cloud Learning Path - Learn how to take your AI projects from prototype to production with the Production-Ready AI with Google Cloud Learning Path. This free series covers security, infrastructure, monitoring, and tools like Gemini models, Vertex AI, GKE, and Cloud Run.

Data Analytics Official Blog

Google is a Leader in the 2025 Gartner® Magic Quadrant for Cloud Database Management Systems - The Gartner 2025 Magic Quadrant for Cloud Database Management Systems positions Google furthest in vision, a testament to our AI-native Data Cloud.

Official Blog Quadrant

Google Named a Leader in the Gartner® Magic Quadrant™ for AI Application Development Platforms - We are proud to announce that Google has been recognized as a Leader in the inaugural 2025 Gartner Magic Quadrant for AI Application Development Platforms for our Ability to Execute and Completeness of Vision.

Official Blog

A new era: Supporting customers as a critical ICT third-party provider under EU DORA - The ESA have officially designated Google Cloud EMEA Limited as a critical ICT third-party service provider under EU DORA. Here’s what that means for our European customers.

Articles, Tutorials

Infrastructure, Networking, Security, Kubernetes

Google Kubernetes Engine Official Blog

How Google Does It: Building the largest known Kubernetes cluster, with 130,000 nodes - Learn about the architectural innovations we used to build a 130,000-node Kubernetes cluster, and the trends driving demand for these environments.

Google Kubernetes Engine

Dynamic and Manual Scaling Strategies in GKE Using Node Auto-Provisioning and Custom Compute Classes - Learn how to optimize your Google Kubernetes Engine (GKE) costs and performance using Node Auto-Provisioning (NAP) and Custom Compute Classes (CCC). These features enable GKE Standard and Autopilot clusters to automatically scale and select the most suitable machine types, including cost-effective Spot VMs, based on actual workload needs.

Docker Kubernetes

Migrating to OCI based Helm chart repositories in order to reduce cloud costs - This article details a real-world migration from legacy to OCI-based Helm repositories on Google Cloud to solve a major issue of excessive data bandwidth usage.

Official Blog Threat Intelligence

Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks - PRC-nexus APT24 uses BADAUDIO malware in a persistent, multi-vector espionage campaign targeting Taiwan.

CISO Official Blog

Cloud CISO Perspectives: Phil Venables on CISO 2.0 and the CISO factory - How is AI affecting the role of the CISO, and how do CISO factories impact that? Phil Venables explains in this newsletter.

Cloud NAT Networking Official Blog

Conquering IP address scarcity: A deep dive into Google Cloud's private NAT - Learn how to use Cloud NAT private NAT to configure private-to-private communication for networks with overlapping IP spaces.

BigQuery Cloud Storage Terraform

Migrating Terraform state from local to GCS bucket - When working with Terraform in a small, individual environment, storing the state file locally is often sufficient.

Official Blog Threat Intelligence

Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem - Tactics, techniques and procedures we discovered during incident response investigations into UNC1549 activity.

App Development, Serverless, Databases, DevOps

Firebase Google Analytics Paywall

How to Set Up a Custom Firebase Auth Domain with Branded Emails (The Complete Guide) - Learn how to set up a custom Firebase auth domain and build Firebase branded emails for a clean, trusted sign-in experience.

BigQuery Cloud Firestore Cloud Run

Migration of cloud components of Cool Maze - Push to Computer - Modernizing app on GCP to improve performance, and optimize costs.

Cloud SQL

Unmasking SQL Server Queries: Who, What, When with Extended Events - This article will guide you through setting up SQL Server Extended Events to accurately capture and analyze your T-SQL queries.

AlloyDB GIS Oracle

Migrating Oracle Spatial Data to PostGIS in AlloyDB/CloudSQL - This guide provides a refined, step-by-step approach for successfully migrating spatial data by converting it to a universally readable text format, routing it through DMS, and leveraging PostgreSQL’s powerful Generated Columns for automatic, real-time spatial re-assembly.

Antigravity and PostgreSQL: No gravity, only vibes - Google Antigravity and Gemini 3 enable full-stack “vibe coding”, making PostgreSQL development a breeze.

Big Data, Analytics, ML&AI

BigQuery Data Science Dataform

How We Cut 80% of Redundant SQL Across BigQuery Using Dataform — Practical Guide - Every analytics engineer has that moment, when your warehouse feels like a junk drawer.

BigQuery Data Analytics Databases Official Blog

TimesFM in Data Cloud: The future of forecasting in BigQuery and AlloyDB - Learn about enhancements to the TimesFM foundation model that performs "zero-shot" forecasting, now available for BigQuery and AlloyDB.

Gemini Generative AI

Structured reasoning: How to architect AI for high-stakes Diligence use cases - This article introduces the Targeted Assessment Agent, a new framework built on Gemini and Google Cloud, which provides the structured reasoning developers need to enhance complex enterprise workflows like due diligence and regulatory compliance.

FinOps Gemini

How CloudHealth partnered with Google Cloud to cut FinOps bot costs by over 99% with Google's Gemini Model - Reducing AI costs.

Agents Official Blog

A methodical approach to agent evaluation: Building a robust quality gate - Learn this structured framework to help you build a robust, tailored agent evaluation strategy so you can trust that your agent can move from a proof-of-concept (POC) to production.

Cloud Run Google Kubernetes Engine Official Blog

Hands-on with Gemma 3 on Google Cloud - Deploy Gemma 3, Google's open model, to production on Google Cloud. Explore two hands-on paths: serverless Cloud Run for simplicity or GKE for robust orchestration.

Agents Official Blog

Four agentic workflows you can build for life sciences for R&D - Deep dive into four agents you can build for life sciences for research and development (R&D). Get started with Google Cloud today, including Vertex AI, Vertex AI Agent Engine, and Vertex AI Search.

AI Big Data Vertex AI

Ray + Vertex AI: The New Architecture for Large-Scale AI/ML Processing - Accelerating large-scale ML and AI pipelines through fully managed Ray Clusters on Vertex AI.

AI Official Blog

A step-by-step guide to fine-tuning MedGemma for breast tumor classification

Gemini Official Blog

Bringing Gemini 3 to Enterprise - Learn, plan, and build with Gemini 3. Available today, you can access Gemini 3 on Vertex AI and Gemini Enterprise.

Gemini Generative AI

MovieLenz: An AI-powered framework for video quality evaluation and prompt optimization - A comprehensive framework that combines video quality assessment, prompt optimization, and iterative refinement to help you generate better videos with AI.

Various

Official Blog Partners

Celebrating our 2025 Google Cloud Partner All-stars - Meet the 2025 Google Cloud Partner All-stars, recognizing exceptional leaders in AI Innovation, Delivery, Sales, and Marketing who are redefining customer success.

GCP Certification

Google Cloud Professional Cloud Architect Renewal: What to Expect & Mastering the New 1-Hour Exam

Slides, Videos, Audio

Security Podcast - #252 The Agentic SOC Reality: Governing AI Agents, Data Fidelity, and Measuring Success.

GCP Bytes Podcast - #30 In this episode we discuss; Cloudflare Outage, Waymo in Sydney, Synthient Breach, GDG Events, Broadcom & VMware, Google Wiz Deal, ACMA Outage Data, Christmas Island DC, Logitech Breach, Fortinet Bypass, Gemini 3, Ironwood TPU, Project Suncatcher, AI Bubble, Amazon vs Perplexity, Nano Banana Pro, Apple & Siri.

 

Releases

AlloyDB - Feature: AlloyDB now supports horizontal autoscaling for read pool instances. This feature is available in Preview. Change: The upper limit of the query plans captured per minute is enhanced to 200. For more information, see Improve query performance using advanced query insights features for AlloyDB. Feature: You can now perform self-service maintenance if you need to apply the latest AlloyDB updates to your clusters as soon as possible. Updating to the latest version can unlock AlloyDB features, apply patches, and let you set deny periods.

Apigee API Hub - Feature: New API deployments view API deployment information is now available as a separate tab in the API details page. You can view your API deployment details, create new deployments, and manage existing deployments using the API deployments tab. For more information, see Manage deployments. Fixed: The issue relating to API hub provisioning failures in data residency enabled Apigee organizations is now resolved. You can now provision API hub within an Apigee organization that has data residency enabled. For information about provisioning API hub, see Provision API hub in the Cloud console. Change: New tutorial: Ingest Microsoft Azure API data into API hub A new tutorial is available for ingesting Microsoft Azure API data into API hub. This tutorial shows you how to ingest API metadata from Azure API Management (APIM) into Apigee API hub. It uses a pre-built Application Integration template and a set of custom scripts on GitHub to perform a manual, on-demand ingestion of your API data. For more information, see Ingest Microsoft Azure API data into API hub.

Apigee UI - Announcement: On November 17, 2025, we released an updated version of the Apigee UI. Fixed: Bug ID Description 446973091 Proxy editor endpoint view is now disabled if there are over 200 flows configured in proxy endpoints. When opening the proxy editor endpoint view with a proxy that has over 200 flows, the proxy graph is no longer rendered, and instead you are presented with a message informing you that there are too many flows to render. This action addresses a performance issue that made the proxy editor unusable when there were over 200 flows configured.

App Hub - Feature: App Hub now supports new metadata properties to provide deeper context and governance for your services and workloads: Functional type: Services and workloads now include the FunctionalType property, which is an output-only field that identifies the known function of a resource. The initial supported value is AGENT, which indicates that a workload is an AI agent. Extended metadata: Services and workloads now include the ExtendedMetadata property to provide rich, structured, and schema-driven information about the resource, such as the apphub.googleapis.com/AgentProperties schema for AI agents. Registration type: Services now have the RegistrationType property. This output-only field indicates whether a service is exclusive (can be registered to only one application) or shared (can be registered to multiple applications). To view the registration type of your services, see View details of services and workloads. Identity: Services and workloads now include the Identity property, which is an output-only field that contains the service account or managed workload identity name for a service or workload.

AppEngine Standard NodeJS - Feature: Support for Node.js 24 runtime is in General Availability.

Cloud Asset Inventory - Feature: The following resource types are publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, Feed, SearchAllResources, and SearchAllIamPolicies APIs. Vertex AI aiplatform.googleapis.com/ReasoningEngine

BigQuery - Feature: You can now use Gemini in BigQuery to fix and explain errors in your SQL queries. This feature is in Preview. Feature: You can use the JSON_FLATTEN function to extract all non-array values that are either directly in the input JSON value or children of one or more consecutively nested arrays in the input JSON value. This function is available in Preview. Feature: Dataform now lets you automate the creation of BigLake tables for Apache Iceberg in BigQuery. This feature is generally available (GA). Feature: You can now use Gemini 3.0 when you call generative AI functions in BigQuery, such as AI.GENERATE. You must use the full global endpoint argument: https://aiplatform.googleapis.com/v1/projects/PROJECT_ID/locations/global/publishers/google/models/gemini-3-pro-preview. Feature: BigQuery ML now supports the following generative AI functions: AI.GENERATE: generate free text to accomplish a wide range of tasks, such as translation, summarization, and classification, on any unstructured data, including images, audio, video, and documents. It can also perform entity extraction and generate structured output. This function is generally available (GA). AI.EMBED: turn text, image, audio, video, or documents into embeddings. This function is in Preview. AI.SIMILARITY: compute the semantic similarity between pairs of text, pairs of images, or across text and images. This function is in Preview. You can use the AI.GENERATE_BOOL, AI.GENERATE_DOUBLE, and AI.GENERATE_INT functions to generate scalar values, which are convenient for filtering, scoring, and counting purposes. Each of these functions supports authentication with end-user credentials (EUC) to set up the necessary Vertex AI permissions. BigQuery ML now supports the following table-valued generative AI functions: AI.GENERATE_TABLE: generate a table of structured output from unstructured data including text, images, audio, and video. AI.GENERATE_TEXT is the new, preferred version of ML.GENERATE_TEXT, which has the same functionality but with simplified column output names. AI.GENERATE_EMBEDDING is the new, preferred version of ML.GENERATE_EMBEDDING, which has the same functionality but with simplified column output names. These functions are all generally available (GA). Feature: You can now publish data insights, including query recommendations and auto-generated table and column descriptions, to the Dataplex Universal Catalog. This feature is in Preview. Feature: You can use folders to organize and control access to single file code assets, such as notebooks, saved queries, data canvases, and data preparation files. This feature is in Preview. Feature: In the query execution graph, you can now use the query text heatmap to identify which query text contributes to stages that consume more slot time, and to see query plan details for those stages. This feature is in Preview. Feature: You can now share SQL stored procedures in BigQuery sharing listings and enable role-based authorization for stored procedures. These features are in preview.

Cloud Composer - Feature: Airflow 3 is available in Preview in Cloud Composer 3. Change: New Airflow builds are available in Cloud Composer 3: composer-3-airflow-3.1.0-build.2 Announcement: All Cloud Composer environment's GKE clusters are set up with maintenance exclusions from December 16, 2025 to January 2, 2025. For more information, see Maintenance exclusions.

Compute Engine - Feature: Preview: The general purpose C4 machine series now supports the following machine types on Intel's Xeon 6 processor (Granite Rapids): c4-standard-288-lssd-metal c4-highmem-288-lssd-metal To learn more, see the C4 machine series. For more information, see Machine types that automatically attach Local SSD disks and Bare metal instances on Compute Engine. Feature: You can autoscale a regional managed instance group (MIG) that has the target distribution shape set to ANY or ANY_SINGLE_ZONE. These shapes are particularly beneficial for batch workloads. For more information about target distribution shapes, see Regional MIG target distribution shape.

Contact Center AI Platform - Announcement: Google Cloud CCaaS 3.42 - full description on the release page.

Database Migration Service - Feature: Database Migration Service now supports the one-time migration type for all heterogeneous migration scenarios. For more information, see the following pages: Migration data flow for Oracle to Cloud SQL for PostgreSQL Migration data flow for Oracle to AlloyDB for PostgreSQL Migration data flow for SQL Server to Cloud SQL for PostgreSQL Migration data flow for SQL Server to AlloyDB for PostgreSQL Feature: Database Migration Service for homogeneous PostgreSQL migrations to Cloud SQL for PostgreSQL now supports PostgreSQL version 18. For more information, see Supported source and destination databases.

Dataform - Feature: Dataform now lets you automate the creation of BigLake tables for Apache Iceberg in BigQuery. This feature is generally available (GA).

Dataplex - Feature: Data products in Dataplex Universal Catalog is now available in preview. A data product serves as a logical, curated package of data assets designed to solve a specific business problem. It enables faster time to insights and provides trust, context, and self-service access request mechanisms for data consumers. For more information, see About data products. Feature: Previously, data profile scan results were published only to the Google Cloud console. You can now publish the results of a data profile scan as Dataplex Universal Catalog metadata. The latest results are saved to the entry that represents the source table. You can view the results in the Google Cloud console. If you want to enable catalog publishing for an existing data profile scan, you must edit the scan and re-enable the publishing option. For more information, see Use data profiling. This feature is generally available (GA).

Datastream - Feature: Datastream now supports partitioning and clustering for BigQuery destinations. For more information, see the documentation.

Cloud NGFW - Feature: You can create a Remote Direct Memory Access (RDMA) over converged ethernet (RoCE) Virtual Private Cloud (VPC) network and configure firewall rules that apply to the network. For more information, see Cloud NGFW for RoCE VPC networks. This feature is available in General Availability.

Cloud Functions - Feature: Support for Node.js 24 runtime is in General Availability.

Google Kubernetes Engine - Issue: In GKE versions 1.34.1-gke.2037001 and 1.34.1-gke.2541000, Arm nodes that use an Ubuntu node image might incorrectly use an image with a 64 KB page size instead of the default 4 KB page size. Avoid using version 1.34.1-gke.2037001 and 1.34.1-gke.2541000 for your Ubuntu Arm nodes. Issue: GKE versions earlier than 1.32 don't support direct NFS volume mounts to NFS volumes that exclusively use an NFS protocol greater than NFSv4.0. When using direct NFS volume mounts, Pods on GKE node versions earlier than 1.32 might fail to mount NFS volumes that are configured to only support protocols greater than NFSv4.0 (such as NFSv4.1 or NFSv4.2 ). This issue occurs because the containerized_mounter on these earlier GKE versions uses version 1.2.8 of the nfs-utils package, which doesn't support NFSv4 minor versions. As a result, the mount process fails with the mount.nfs: access denied by server error message. This issue doesn't affect GKE version 1.32 and later, which include an updated version of the nfs-utils package. To resolve this issue, try one of the following options: Upgrade clusters to GKE version 1.32 or later. Configure the NFS volume to support both the NFSv3 and NFSv4 protocols, which allows the mount to succeed by falling back to a compatible version. Use a PersistentVolume and PersistentVolumeClaim to mount the NFS volume, which allows for explicit NFS version specification. Change: (2025-R48) Version updates GKE cluster versions have been updated. New versions available for upgrades and new clusters. The following versions are now available for new GKE clusters, and for manual control plane upgrades and node upgrades for existing clusters. For more information about versioning and upgrades, see GKE versioning and support and About GKE cluster upgrades. Rapid channel Note: Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to complete across all Google Cloud zones. The following versions are now available in the Rapid channel: 1.31.13-gke.1454000 1.32.9-gke.1548000 1.33.5-gke.1791000 1.34.1-gke.2980000 1.34.1-gke.3084001 Regular channel Note: Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to complete across all Google Cloud zones. The following versions are now available in the Regular channel: 1.31.13-gke.1231000 1.32.9-gke.1330000 1.33.5-gke.1521000 Stable channel Note: Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to complete across all Google Cloud zones. There are no new releases in the Stable channel. Extended channel Note: Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to complete across all Google Cloud zones. The following versions are now available in the Extended channel: 1.28.15-gke.3163000 1.29.15-gke.2467000 1.30.14-gke.1719000 No channel Note: Your clusters might not have these versions available. Rollouts are already in progress when we publish the release notes, and can take multiple days to complete across all Google Cloud zones. The following versions are now available: 1.31.13-gke.1454000 1.32.9-gke.1548000 1.33.5-gke.1791000 The following node versions are now available: 1.28.15-gke.3163000 1.29.15-gke.2467000 1.30.14-gke.1719000 1.31.13-gke.1454000 1.32.9-gke.1548000 1.33.5-gke.1791000 Security: (2025-R48) Security updates This release includes new GKE versions that use updated Container-Optimized OS images. These updated images are cumulative, incorporating security fixes from all Container-Optimized OS versions released since the previous GKE release. To identify the specific vulnerabilities that were resolved in each updated Container-Optimized OS image, see the Security release notes for that image. The following table includes links to the release notes for each updated Container-Optimized OS image: GKE version Container-Optimized OS version Details 1.28.15-gke.3163000 cos-113-18244-521-16 cos-113-18244-521-16 release notes 1.29.15-gke.2467000 cos-113-18244-521-16 cos-113-18244-521-16 release notes 1.30.14-gke.1719000 cos-113-18244-521-16 cos-113-18244-521-16 release notes 1.31.13-gke.1454000 cos-117-18613-439-22 cos-117-18613-439-22 release notes 1.32.9-gke.1548000 cos-117-18613-439-22 cos-117-18613-439-22 release notes 1.33.5-gke.1791000 cos-121-18867-294-17 cos-121-18867-294-17 release notes 1.34.1-gke.2980000 cos-125-19216-0-115 cos-125-19216-0-115 release notes Feature: NVIDIA recommends that Kubernetes clusters enable Coherent Driver-Based Memory Management (CDMM) to resolve memory over-reporting. CDMM is enabled by default on A4X nodes running the R580 GPU driver in GKE clusters with the following versions: 1.33 or later: 1.33.4-gke.1036000 or later 1.32: 1.32.8-gke.1108000 or later CDMM allows GPU memory to be managed through the driver instead of the operating system (OS), avoiding OS onlining of GPU memory, and exposing the GPU memory as a Non-Uniform Memory Access (NUMA) node to the OS. For more information about CDMM, see Hardware and Software Support. To create GKE clusters with A4X, see the following documents: Create an AI-optimized GKE cluster with default configuration Create a custom AI-optimized GKE cluster which uses A4X

Looker - Feature: The content certification feature, when enabled, lets trusted users certify Looker dashboards and Looks to indicate that the content has gone through a manual review and is certified as reliable and trustworthy. This lets other users identify reliable content and confidently use that data for decision-making. Note: This item was updated on November 20, 2025.

Memorystore for Redis Cluster - Feature: The /node/server/healthy metric is Generally Available.

Migration Center - Feature: Preview: Migration Center now provides more granular storage preferences for Compute Engine. You can now specify your preference for using Hyperdisk Storage Pools to reduce costs and improve operational efficiency. For more information, see Migration preferences for servers. Issue: If you select sole-tenant nodes as your migration target, Migration Center always recommends Hyperdisk Storage Pools even if they are more expensive than individual Hyperdisk volumes. When migrating to sole-tenant nodes, we recommend that you select Never in the Hyperdisk Storage Pools section of your preferences. For more information, see Migration preferences for servers.

Cloud Run - Feature: Configure HTTP and gRPC readiness probes for your Cloud Run services (Preview). Feature: Deploy a highly available, multi-region Cloud Run service with automated failover and failback for internal traffic using Cloud Run service health (Preview). Feature: Support for Node.js 24 runtime is in General Availability. Feature: You can deploy source artifacts directly to Cloud Run, bypassing the Cloud Build step. (Preview) Feature: Cloud Run and Cloud Run functions source deployments support pyproject.toml file for managing dependencies. If you use a pyproject.toml file, source deployments use one of the following to find and install dependencies: pip uv poetry For more information, see Deploy Python applications with a pyproject.toml file (Preview).

Security Command Center - Change: The following updates simplify Security Command Center Standard and Premium tier activation for organizations: You need fewer Identity and Access Management (IAM) roles to activate Security Command Center. A variety of services are automatically enabled during activation. Service-specific service agents are automatically enabled with the IAM roles and permissions that are required for these services to function. See the following for detailed information about activating a specific tier: Activate Security Command Center Standard tier for an organization Activate Security Command Center Premium tier for an organization Feature: The following AI Protection features are available: AI Security dashboard: The dashboard has an updated AI Inventory section, which includes an overview of AI agents. Assets page: You can filter for AI resources, including AI agents that are deployed to Vertex AI Agent Engine. AI Protection is available in Preview to the Security Command Center Enterprise tier. Feature: Agent Engine Threat Detection, a built-in service of Security Command Center, is available in Preview to the Security Command Center Enterprise and Premium tiers. This service helps you detect and investigate potential attacks on AI agents that are deployed to Vertex AI Agent Engine Runtime.

Service Extensions - Feature: For authorization extensions, in addition to the ext_proc Envoy gRPC API, the ext_authz gRPC API is also supported. This capability allows seamless integration with the broader authorization ecosystem. This feature is in Preview.

Service Mesh - Announcement: The following rollouts have completed for managed Cloud Service Mesh: 1.21.6-asm.4 has rolled out to the rapid release channel. 1.20.8-asm.56 has rolled out to the regular release channel. 1.19.10-asm.52 has rolled out to the stable release channel. CNI and MDPC version 1.20.8-asm.56 has rolled out to all release channels. While the managed data plane automatically updates Envoy Proxies by restarting workloads, you must manually restart any StatefulSets and Jobs.

Cloud Spanner - Feature: Query optimizer version 8 is now the default version for Spanner.

Cloud SQL MySQL - Feature: To help prevent out-of-memory (OOM) events, you can enable managed buffer pool for Cloud SQL for MySQL 8.0 and later instances. When you enable managed buffer pool, Cloud SQL reduces the value of the innodb_buffer_pool_size configuration and frees up memory when memory usage is high, and the instance is in danger of an OOM event. After memory usage stabilizes at a lower value, MySQL increases the value of innodb_buffer_pool_size incrementally to its original value. To enable managed buffer pool, your Cloud SQL instance must use a maintenance version of [$MYSQL_VERSION].R20251004.01_07 or later. You can't enable managed buffer pool for instances that use a shared core or for instances that are running MySQL 5.6 or MySQL 5.7. For more information, see Enable managed buffer pool. Support for managed buffer pool is in Preview. Feature: Cloud SQL for MySQL 8.4.6 is upgraded to MySQL 8.4.7. For more information, see the MySQL 8.4.7 Release Notes. Feature: Cloud SQL now offers a free trial instance for both existing and new Google Cloud customers. A free trial instance lets you test advanced Cloud SQL capabilities and features for up to 30 days without any financial commitment. For information about a free trial instance, and its inclusions and conditions, see Free trial instance overview.

Cloud SQL Postgres - Feature: PostgreSQL version 18 is now generally available for Cloud SQL for PostgreSQL. You can now use Database Migration Service with Cloud SQL for PostgreSQL when using PostgreSQL version 18. To upgrade your instance to PostgreSQL 18, see Upgrade the database major version in-place. The following extensions are also now available for PostgreSQL 18: pg_hint_plan pgrouting anonymizer pg_wait_sampling tds_fdw plpgsql_check For more information about these extensions, see Configure PostgreSQL extensions. Feature: The rollout of the following minor version and extension upgrades is complete: Minor versions 13.22 is upgraded to 13.23. 14.19 is upgraded to 14.20. 15.14 is upgraded to 15.15. 16.10 is upgraded to 16.11. 17.6 is upgraded to 17.7. 18 is upgraded to 18.1. Extensions Pgvector is upgraded from 0.8.0 to 0.8.1. To use these versions of the extensions and plugins, update your instance to [PostgreSQL version].R20251004.01_19. If you use a maintenance window, then the updates to the minor, extension, and plugin versions happen according to the timeframe that you set in the window. Otherwise, the updates occur within the next few weeks. For more information on checking your maintenance version, see Self-service maintenance. To find your maintenance window or to manage maintenance updates, see Find and set maintenance windows. Feature: Cloud SQL for PostgreSQL now supports Vector assist ( Preview ). Vector assist is a Cloud SQL for PostgreSQL extension that simplifies the deployment and management of your Cloud SQL vector workloads. It helps you set up production-ready vector search capabilities, such as embedding generation, query optimization, and index creation. For more information about vector assist, how it works, and its limitations, see Vector assist overview. Feature: Cloud SQL now offers a free trial instance for both existing and new Google Cloud customers. A free trial instance lets you test advanced Cloud SQL capabilities and features for up to 30 days without any financial commitment. For information about a free trial instance, and its inclusions and conditions, see Free trial instance overview.

Vertex AI Workbench - Feature: The M135 release of Vertex AI Workbench instances includes the following: Patched an issue where user-triggered OS shutdowns aren't reported to the Notebooks API.

 

Latest Issues




Contact

Zdenko Hrček
Třebanická 183
Prague, Czech Republic
Phone: +420 777 283 075
Email: [email protected]