Welcome to issue #510 July 6th, 2026

News

Gemini LLM

Bringing speed and strong cost performance to the market with Gemini Omni Flash and Nano Banana 2 Lite - We’re adding two new models to Gemini Enterprise Agent Platform. Nano Banana 2 Lite (Gemini 3.1 Flash-Lite Image) is available for everyone, and Gemini Omni Flash is available in public preview. Read more to get started.

AI AlloyDB

AlloyDB AI Functions - now with revolutionary performance boosts and cost savings - Discover how AlloyDB AI functions bring Gemini’s intelligence to your data while accelerating query speed and reducing costs.

Cloud Monitoring

Anomaly detection using dynamic thresholds and two-year-long alerts in Cloud Monitoring - Long-lookback alert policies for PromQL cover up to two years of metrics in Cloud Monitoring for year-over-year and quarter-over-quarter analysis.

Agents BigQuery

Conversational analytics in BigQuery brings trusted agentic reasoning to everyone - Use Conversational Analytics in BigQuery to query data, run analyses, and generate reports using natural language on data in BigQuery and Lakehouse.

Generative AI LLM

Get started with the Claude apps gateway for Google Cloud - The Claude apps gateway is a self-hosted service that sits directly between your local Claude Code clients and Gemini Enterprise Agent Platform. This post breaks down why you should run it and what secure deployment looks like on Google Cloud.

Public Sector

Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval - We understand that for the EU public sector, data protection is a prerequisite. We’re excited to reinforce this commitment with a major milestone.

Data Analytics Quadrant

Google named a Leader in 2026 Gartner® Magic Quadrant™ for Analytics and Business Intelligence Platforms for third year in a row - Looker ranked in the 2026 Gartner Magic Quadrant for Analytics and Business Intelligence Platforms for the third year in a row.

Articles, Tutorials

Infrastructure, Networking, Security, Kubernetes

Security

New IDC study: The business value of Mandiant Consulting - A new IDC Business Value White Paper found that you save an average of $4.3 million, driving a 268% three-year ROI, with Mandiant Consulting.

Threat Intelligence

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem - A look at the Pro-Russia influence ecosystem driven by the Russian Government to advance Kremlin interests globally and domestically.

CISO Security

Cloud CISO Perspectives: How Google Cloud Security uses AI internally - Following our AI Threat Defense announcement, here's how we use AI to chart a path to autonomous software development lifecycle security.

Security Threat Intelligence

Google’s Continued Disruption of Malicious Residential Proxy Networks - Google disrupted the NetNut malicious residential proxy network, protecting over 2 million hijacked consumer devices from cybercriminals.

Google Cloud Managed Lustre Google Kubernetes Engine LLM

Scaling LLM Inference: Multi-Node KV Cache Offloading with GKE & Managed Lustre - Scale enterprise LLM inference using GKE and Google Cloud Managed Lustre. Learn to offload KV caches for better long-context support and reduced GPU-hour costs.

Antigravity Google Kubernetes Engine Kubernetes SRE

100x SRE: Building an Agentic GKE Capacity Optimizer with Google Antigravity 2.0 - This article details how to build an agentic GKE capacity optimizer using Google Antigravity 2.0 and Custom Compute Classes. This solution addresses the problem of "Pending Pods" and manual resource management by dynamically generating optimal GKE manifests based on workload demands and market conditions. It provides a human-in-the-loop approval process, shifting the cognitive load from SREs for more efficient and cost-effective Kubernetes cluster provisioning.

App Development, Serverless, Databases, DevOps

Agents Cloud Spanner

Supercharging the agentic era with Spanner’s multi-model architecture - Spanner unifies relational, vector, graph, key-value, and full-text search data directly within a single, highly performant database architecture.

AlloyDB

Modernizing financial services with deployment freedom and transformational AI with AlloyDB Omni - Modernize financial workloads with AlloyDB Omni. Get enterprise security, DORA compliance, and real-time AI in a hybrid PostgreSQL database.

ChromeOS GCP Experience

Turner Industries’ Blueprint for a Secure, Cloud-First Infrastructure - How Turner Industries saved more than $1 million and over 1,700 hours with ChromeOS and ChromeOS Flex.

AlloyDB GCP Experience Gemini

SOCRadar powers rapid threat detection with AlloyDB and Gemini Enterprise - SOCRadar replaced its on-prem, self-managed databases so it could keep pace with the simultaneous demands of high-velocity data ingestion and heavy, real-time analytical queries.

AI AI Platform Notebooks

ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available - The Google Cloud Workbench Notebooks extension for VS Code has officially launched, allowing developers to connect their local IDE to scalable, cloud-based Jupyter environments. This integration streamlines the machine learning lifecycle by eliminating context switching and providing direct access to high-performance Google Cloud infrastructure. To support transparency and community-driven innovation, the newly released extension is fully open-sourced and available on GitHub and the VS Code Marketplace.

Gemini Vertex AI

What Your Unrestricted Gemini API Key Can Do to Your GCP Bill - Unrestricted Gemini API keys, while easy to generate, pose significant security and cost risks on GCP if left unprotected or leaked. This article details crucial preventative measures, such as restricting key usage, securely storing them, and prioritizing Vertex AI for production workloads due to its superior IAM and network controls. It further explains how to implement comprehensive cost monitoring, attribution, and real-time alerting using labels, structured logging, and BigQuery exports to manage expenses effectively.

Cloud Run Serverless

Locally test your Cloud Run service code that makes an authenticated call to another Cloud Run service - This guide explains how to locally test a Cloud Run service that makes authenticated calls to another Cloud Run service using ID Tokens. It provides practical code examples and configuration steps for setting up your local environment, including service account impersonation.

Big Data, Analytics, ML&AI

BigQuery Networking

Scaling Network Analysis for Fraud Prevention with BigQuery Graph - Data analysis at scale to identify hidden fraud and achieve transaction savings.

Big Data BigQuery Paywall

Stop Optimizing BigQuery Until You Run These 5 INFORMATION_SCHEMA Queries - Most BigQuery optimization starts in the wrong place.

BigQuery FinOps

BigQuery Fluid Scaling: the numbers are in! - Google Cloud's new BigQuery Fluid Scaling dramatically improves reservation billing by eliminating the previous 60-second minimum, shifting to precise per-second consumption. This change significantly reduces "cooldown waste," making reservations much more cost-effective and suitable for bursty workloads, thus simplifying cost analysis and reinforcing BigQuery's serverless capabilities.

AI BigQuery

Synthesize the big picture and analyze trends with BigQuery's AI.AGG function - Learn to use BigQuery’s new AI.AGG function to analyze unstructured data such as logs and documents at scale.

Machine Learning

How Schrödinger sped up molecular discovery by 4x with Alphaevolve - Machine-learned force fields are powerful scientific computational tools, but they face constraints when searching large datasets. The evolutionary algorithms of Alphaevolve close the gap.

Gemini Enterprise Agent Platform MCP

Build agents even faster with Gemini Enterprise Agent Platform’s fully-managed, remote MCP server - Learn how to use the Gemini Enterprise Agent Platform remote MCP server to securely connect your external AI agents to the resources inside your Google Cloud environment.

Gemini

Web manual-like QA with Gemini - This article demonstrates how to automate manual-like QA testing using Google Cloud's Gemini and its "Computer Use" capability. This innovative AI browser automation visually perceives and interacts with web pages, driving them like a person from screen pixels to ensure robust testing that withstands UI changes. Integrated into CI/CD pipelines, this solution provides automated, natural language-driven QA for every pull request.

JAX Machine Learning TPU

From 1,540 to 15,338 Tokens per Second on a Single TPU Chip - This study significantly optimized large language model inference on a single Google TPU v5e chip, increasing throughput from 1,540 to 15,338 tokens per second. This tenfold gain was achieved through meticulous measurement and refinement of software configurations, without altering the model or hardware. The findings demonstrate substantial improvements in cost and energy efficiency, highlighting the potential of moving beyond default serving setups.

ADK Agents

Beyond Static Prompts: Building Scale-Proof, Polymorphic Multi-Agent Systems with Google's ADK - Scale enterprise AI with Google's ADK. Discover a polymorphic multi-agent architecture that solves context bloat and attention diffusion using dynamic, metadata-driven validation.

ADK AI

Why we built ADK 2.0 - Answering the questions of "why we built ADK 2.0". This explains the rationale, some of the features, and why a developer should consider upgrading. This will be published the day after ADK go 2.0 launches.

ADK Agents AI

Build reliable multi-agent applications with ADK Go 2.0. Discover our new graph-based workflow engine, built-in human-in-the-loop, and dynamic orchestration - The Agent Development Kit (ADK) for Go 2.0 has been released, introducing a first-class, graph-based workflow engine to help developers compose complex, multi-agent applications. This update adds built-in primitives for human-in-the-loop (HITL) orchestration, dynamic execution using plain Go code, and automated resilience features like exponential backoff retries. By unifying the execution model, both single-agent applications and intricate graphs now run on the same runtime, simplifying telemetry and state persistence.

Agents AI Go Typescript

Build agentic full-stack apps with Genkit - The open-source Genkit framework has introduced the Agents API, a full-stack tool designed to simplify the complex plumbing of conversational AI by packaging message history, tool loops, and streaming into a single interface. The API supports flexible, server- or client-managed state persistence—allowing for advanced workflows like history branching, long-running detached tasks, and multi-agent coordination—while seamlessly connecting backends to frontends via a unified wire protocol. Currently available in preview for TypeScript and Go, it also integrates with the Genkit Developer UI to allow developers to easily test, debug, and inspect agent snapshots without writing client code.

Agents AI

Driving the Agent Quality Flywheel from Your Coding Agent - Building AI agents often leaves developers uncertain if prompt tweaks to fix single errors will accidentally cause widespread regressions in production. To bridge this gap, Google has introduced a new developer skill for coding agents that automates a five-stage evaluation flywheel: preparing data, running inference, grading with adaptive AutoRaters, analyzing failure clusters, and executing targeted optimizations. Running continuously against production traffic or on-demand via synthetic scenarios, this tool allows developers to describe testing goals in plain language while an independent evaluation service safely validates and counts actual performance improvements.

Cloud Monitoring Cloud Run Cloud Trace Gemini

Monitoring multi-agent reasoning latency & token costs: Distributed tracing with OpenTelemetry and Google Cloud Trace

BigQuery Gemini Terraform

Gemini Enterprise: Building a Periodic BigQuery Search Agent with Terraform - In the era of Generative AI, Large Language Models are only as smart as the enterprise data you give them.

LLM

Decoding the deep geometry of enterprise embeddings: The definitive guide to Google’s Vertex AI, Gecko, and Vector Physics - This comprehensive guide offers an engineering deep-dive into Google Cloud's Vertex AI text embeddings, particularly gemini-embedding-001, detailing their mathematics and backend architecture. It explains how these advanced models power enterprise AI applications like RAG and semantic search, covering innovative features such as multilingual support, Matryoshka Representation Learning, and crucial production considerations like chunking and drift detection.

Slides, Videos, Audio

GCP Bytes Podcast - #44 In this episode we discuss; C64, Proxmox, Euro Office, Webmarker, Fridges, EY, Sonnet 5 & Fable, GDG, Tesco, E-Safety Commissioner, Bendigo Bank Security, Google Top 10 for 2026, Gemini Review Bot, Google Bug Bounty, Anthropic no longer a threat, LLM Bottlenecks, LLM Memory Bus Improvements, GLM5.2, Google Limits Meta, Meta Saving DDR4, First Vibe Coded Game.

 

Releases

Apigee Hybrid - Various security and CVE fixes are included in this release. v1.15.5 On July 3, 2026 we released an updated version of the Apigee hybrid software, v1.15.5. For information on upgrading, see Upgrading Apigee hybrid to version v1.15.5. For information on new installations, see The big picture. Note: This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see Apigee release process.

AppEngine Flexible - Support for deploying your existing apps in the flexible environment to Cloud Run using the gcloud beta app migrate-to-run command is in Preview. For more information, see Deploy an App Engine app in the flexible environment to Cloud Run.

BigQuery - You can now grant data preparations and pipelines access to additional services when running or scheduling them with user credentials for a Google Account. You can grant data preparations access to Google Drive, and grant pipelines access to Google Drive, Bigtable, and Knowledge Catalog. Extended access options are available in Preview. Effective March 9, 2026, new users are required to have a Cloud Billing account to use the BigQuery Migration Service. This change applies to users starting new projects using BigQuery Migration Service features, such as SQL translation and migration assessment. After May 18, 2026, all users are required to have a Cloud Billing account to use the BigQuery Migration Service. Pricing for the BigQuery Migration Service remains without charge. You can specify an optional principal property on BigQuery reservation assignments to route queries to specific reservations based on the identity of the user, service account, or third-party identity executing the job. You can now use pre-trained TimesFM models in BigQuery ML directly from Connected Sheets. These models let you create forecasts and detect anomalies in your data by using the AI.FORECAST and AI.DETECT_ANOMALIES functions. This feature is generally available (GA).

CDN - Cloud CDN and external Application Load Balancers support self-service Private Bucket Access for Cloud Storage buckets. This feature allows you to securely serve content without making your storage buckets public. The access on the buckets is managed securely via IAM permissions on a Google-managed service account. This feature is Generally Available. For more information, see Private bucket access.

Chronicle - Unified rules interface The new rules interface is now available in public preview. The Google SecOps unified rules interface brings custom and curated rule management into a single, cohesive workflow. This optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting. You can still revert to the legacy experience. At the top right of the screen, click Switch to the legacy experience. For more information about the Unified rules interface, see Manage unified rules. [Spotlight Feature] Security Tokens Security Tokens are now available for metering agentic consumption within Google SecOps. Tokens are consumed by generally available security agents only. These agents are invoked automatically or manually using the web interface, CLI, chat, or Model Context Protocol (MCP). Assistive features, such as standard chat panels and automated summaries, along with preview agents, won't consume Security Tokens. Security Tokens will start rolling out across all regions starting July 1. For more information, see Google SecOps Agentic SOC Security Tokens pricing and billing.

Chronicle SOAR - Release 6.3.91 is now available for all regions. Release 6.3.92 is being rolled out to the first phase of regions as listed here. This release contains internal and customer bug fixes.

Cloud Composer - New images are available in Managed Airflow (Gen 2): composer-2.17.5-airflow-2.11.1 (default) composer-2.17.5-airflow-2.10.5 A new Managed Service for Apache Airflow release has started on June 29, 2026. Get ready for upcoming changes and features as we roll out the new release to all regions. This release is in progress at the moment. Listed changes and features might not be available in some regions yet. New Airflow builds are available in Managed Airflow (Gen 3): composer-3-airflow-3.1.7-build.12 composer-3-airflow-2.11.1-build.8 (default) composer-3-airflow-2.10.5-build.41

Cloud Monitoring - Alerting policies based on PromQL queries can now operate over more than 25 hours of data. For more information, see Query over 2 years of metric data and Limits for alerting.

Cloud NAT - Preview: Cloud NAT gateways for Private NAT support IPv6 to IPv4 network address translation. For more information, see NAT64 in Private NAT.

Cloud Run - Deploy a highly available, multi-region Cloud Run service with automated failover and failback for internal and external traffic using Cloud Run service health in General Availability (GA). Configure HTTP and gRPC readiness probes for your Cloud Run services is in General Availability (GA).

Cloud SQL MySQL - MySQL 8.0.45 is now the default minor version for Cloud SQL for MySQL 8.0. For more information about minor version support in Cloud SQL for MySQL, see MySQL 8.0.

Cloud Trace - Google Cloud Observability has expanded the supported locations for observability buckets, which store your trace data, to include the following: europe-west9 For a list of supported locations, see Locations for observability buckets.

Contact Center AI Platform - Full details are on the release page.

Dataform - You can grant workflows access to Bigtable, Google Drive, and Knowledge Catalog when running or scheduling them with your Google Account user credentials. Extended access options are available in Preview.

Looker - Looker (Google Cloud core) has introduced release channels in preview, allowing users to choose between Rapid, Regular, and "No channel" options to manage the cadence of version updates. The Rapid channel provides early access to new capabilities but is excluded from the Service Level Agreement (SLA), while the Regular channel offers balanced stability with an optional Accelerated Security Patching flag. The latest versions in the Looker (Google Cloud core) release channels are beginning deployment as follows: Latest version in the Rapid channel: 26.10 Latest version in the Regular channel: 26.10 Latest version in the No Channel channel: 26.10

NetApp - The Flex Unified service level supports the optional feature Block volume from deletion when clients are connected for both block and file volumes. This option is required for using NetApp Volumes with Google Cloud VMware Engine (GCVE) datastores. When this option is enabled, it prevents the deletion of a volume if the volume is mounted as a GCVE datastore. The Flex Unified Default-mode service level supports the thick clone (thin clone split) feature in Preview. For more information, see Manage volume clones.

Sensitive Data Protection - You can configure Sensitive Data Protection to detect specific file labels, which can represent Google Drive labels or Microsoft sensitivity labels. For more information, see Create a custom metadata label detector.

Service Mesh - 1.29.5-asm.5 is now available for in-cluster Cloud Service Mesh. This patch release contains the fix for the security vulnerability listed in GCP-2026-045. For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.29.5-asm.5 uses Envoy v1.37.5. 1.28.9-asm.4 is now available for in-cluster Cloud Service Mesh. This patch release contains the fix for the security vulnerability listed in GCP-2026-045. For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.28.9-asm.4 uses Envoy v1.36.9. 1.27.9-asm.9 is now available for in-cluster Cloud Service Mesh. This patch release contains the fix for the security vulnerability listed in GCP-2026-045. For details on upgrading Cloud Service Mesh, see Upgrade Cloud Service Mesh. Cloud Service Mesh 1.27.9-asm.9 uses Envoy v1.35.13. Proxy version csm_mesh_proxy.csm_mesh_proxy.20260624e_RC01 for Gateway API on GKE clusters is rolling out to all Managed Cloud Service Mesh release channels over the next week. This patch release contains the fixes for the security vulnerabilities listed in GCP-2026-040.

VPC Service Controls - VPC Service Controls feature: Support for using the following identities in ingress and egress rules to allow access to resources protected by a service perimeter is generally available: Agent identities SPIFFE formats for third-party workforce and workload identities For more information, see Configure identity groups and third-party identities in ingress and egress rules and Supported identities for ingress and egress rules.

Vertex AI Workbench - Python 3.12 base containers for Agent Platform Workbench custom containers You can build custom containers for Agent Platform Workbench instances using Python 3.12 base containers, in addition to the default Python 3.10 base containers. The Python 3.12 standard and slim base containers are available at the following URIs: us-docker.pkg.dev/workbench-images/gcr.io/workbench-container-2606:latest us-docker.pkg.dev/workbench-images/gcr.io/workbench-container-slim-2606:latest

Virtual Private Cloud - General Availability: If a consumer VPC network uses an RDMA network profile for Falcon VPC networks, a single Compute Engine instance can connect to it by using multiple virtual Private Service Connect interfaces. For more information, see Create VMs with Private Service Connect interfaces.