Welcome to issue #517 August 24th, 2026
News
Cloud KMSOfficial BlogAnnouncing quantum-safe key import in Cloud KMS - We’re excited to announce the preview of quantum-safe key import in Cloud KMS for software-based cryptographic keys, a pioneering BYOK capability.
AntigravityOfficial BlogExpanding Google Antigravity for enterprise customers - Today, we are excited to expand access to Antigravity to help even more customers and developers accelerate software delivery, with the security and control organizations need to innovate at scale.
AlloyDBDatabasesOfficial BlogHow AlloyDB ScaNN scales vector search to 10 billion vectors - The new four-level tree in AlloyDB ScaNN index now operates efficiently at a scale of 10 billion vectors, satisfying the demands of modern benchmarks.
Official BlogQuadrantServerlessGoogle is a Leader in the 2026 Gartner® Magic Quadrant™ for Cloud-Native Application Platforms - As a 2026 Gartner Magic Quadrant for Cloud-Native Application Platforms Leader, we help developers focus on their apps rather than infrastructure.
Articles, Tutorials
Infrastructure, Networking, Security, Kubernetes
Official Blog Threat IntelligenceGoing with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia - Distinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account compromise. This piece follows up on and expands upon our blog from last year on UNC6293’s ASP phishing to show these threat actors’ evolution, highlighting these additional TTPs.
CISO Official BlogCloud CISO Perspectives: Sticking to security fundamentals in the AI era - In the AI era, we need to bolster security fundamentals more than ever. CISO Chris Betz explains why, and how Google Cloud can help you.
TerraformCodifying FreshCart: Building a Reproducible Two-Tier GCP Architecture with Terraform - This article explores the transition from manual infrastructure management to reproducible Infrastructure as Code by rebuilding a two-tier Google Cloud architecture using Terraform. It details how modularizing networking, backend services, and load balancers enables seamless environment reuse, parameterization, and drift detection.
AI Official Blog Threat IntelligenceStaying Ahead of Adversarial AI Through Agentic Source Code Review - This blog describes the methodology that powers a Mandiant internal tool for point-in-time AI vulnerability discovery. It has discovered hundreds of vulnerabilities in customer codebases and resulted in dozens of vendor notifications with either assigned or pending CVE numbers. We are sharing the details of this internal architecture to help network defenders conceptualize similar approaches for their own environments.
App Development, Serverless, Databases, DevOps
Agents AI GCP Experience Official BlogBuilding operational resilience with agentic AI in financial services - Needing to maintain operational resilience in the age of AI, Deutsche Bank deployed agentic tools from Google Cloud to satisfy workers and regulators.
Cloud Run Compute Engine GPUI Thought Cloud Run Was the Perfect Fit for My GPU Workload… Until I Needed More Control - This article explores reasons to transition a GPU workload from Google Cloud Run to a Managed Instance Group (MIG).
Cloud Run Cloud SchedulerHow I Connected Prefect Cloud to GCP Cloud Run Jobs Without a Paid Subscription - This article explains how to integrate Prefect Cloud with Google Cloud Run Jobs and Cloud Scheduler to monitor data-ingestion workflows for free, avoiding paid subscription fees. By leveraging GCP for scheduling and execution while connecting containers to Prefect Cloud using Secret Manager, developers can achieve full pipeline visibility and log tracking at zero additional cost.
Cloud Run MCPDeploying Secure MCP Servers on Cloud Run - This article demonstrates how to scale AI workflows by transitioning Model Context Protocol (MCP) servers from local workstations to production-ready endpoints on Google Cloud Run. It provides a practical guide using Python and FastMCP to build the server, secure it with Google Cloud IAM authentication, and seamlessly connect it to local coding assistants like Claude Code.
Gemini Gemini Enterprise Agent Platform LLMGemini Play Smart — a 429-survival capacity ladder - This article introduces the "capacity ladder" strategy as a cost-effective alternative to purchasing Provisioned Throughput for handling `RESOURCE_EXHAUSTED` (429) errors when working with the Gemini API on Google Cloud.
AI Generative AI Official Blog Startups10 questions every startup should answer before moving to production with their AI prototype - 10 questions every startup should be ready to answer before they scale, grouped into the three phases where decisions can shape your future.
Agents Cloud SpannerX-Ray Your Agent Fleet - This article explores how developers can uncover cost drains, architectural bottlenecks, and security bypasses in multi-agent AI systems by analyzing OpenTelemetry traces as a single graph. Using built-in graph algorithms within Google Cloud Spanner, engineering teams can evaluate thousands of agent interactions simultaneously rather than debugging sessions one by one.
Big Data, Analytics, ML&AI
BigQuery FinOpsHow to Cut GCP Data Pipeline Costs by 60% Without Slowing Them Down - A practical guide to optimize BigQuery, Dataflow, Cloud Storage, Composer, and the engineering habits around them.
Apache IcebergA Practical Blueprint for Google Cloud’s Lakehouse with Iceberg - Catalog topology, namespace IAM gotchas, FinOps chargebacks, and making multi-tenant data mesh actually work on Google Cloud.
BigLake Data Analytics Official BlogHow to modernize Apache Hive using Google Cloud’s Lakehouse runtime catalog - Google Cloud Lakehouse runtime catalog provides a runnable, zero-data-copy migration to transition your production Apache Hive tables.
Data Analytics Official BlogGovernance on autopilot, minus the turbulence - Learn how to automate data governance by using column-level lineage to propagate metadata, reducing manual audit work and keeping data context current.
BigQueryYour BigQuery Bill Is Doing Cardio: A Zero-Data-Loss BigQuery Partitioning Runbook - A production-grade migration strategy for partition pruning, clustering, CDC consistency, validation, rollback, and cost control.
BigQuery DataformWhen to consolidate scheduled queries into Dataform - This article explores the tipping point when managing multiple independent BigQuery scheduled queries becomes unsustainable and transitioning to Google Cloud's Dataform is necessary.
Cloud Run Gemma LLMFine-Tuning and Deploying Gemma 4 at Scale on Gemini Enterprise Agent Platform (GEAP) and Cloud Run - A Healthcare Guide to Supervised Fine-Tuning, Knowledge Distillation, and Sub-Second GPU Inference.
BigQueryAdding new fields to a nested BigQuery schema: the workaround that actually works - This article explains how to bypass BigQuery's limitation with the `ALTER TABLE` command when trying to add new fields to nested schemas, such as GA4 export tables.
Data Analytics Official Blog Serverless Spark StreamingServerless Apache Spark on Google Cloud: Architecture Choices & AI Troubleshooting - Learn to choose Apache Spark deployment models, optimize costs, and troubleshoot serverless pipelines on Google Cloud with Gemini Cloud Assist.
Agents Cloud Dataflow Data Analytics Generative AI Official Blog StreamingBuilding cost-effective, high-throughput gen AI workflows in Google Dataflow - Learn how to build cost-effective, high-throughput GenAI streaming workflows in Google Dataflow using sentiment pre-filtering and agentic actions.
BigQuery dbt PaywallSCD Type 2 on BigQuery: Stop Rewriting the Partition That Never Changes - This article explores how to optimize Slowly Changing Dimension (SCD) Type 2 tables in Google Cloud BigQuery by rethinking how data is partitioned and updated.
Agents Data Analytics Python Serverless SparkFrom prompt engineering to agentic workflow: Building intelligent systems on Dataproc Serverless part 1 - This article explains how to transition from traditional manual development to autonomous agentic workflows by automating the Git-to-Google Cloud Storage build pipeline. Using Python, SBT, and Google Cloud tools, the guide demonstrates how to encapsulate complex compilation steps into a reliable, programmatic format that AI agents can execute via natural language.
AI Databricks FinOpsOne Calculator, Four Front Doors: Building an AI‑Native TCO Tool for Databricks on Google Cloud - This article explores how to modernize an existing calculation engine by delivering a single Total Cost of Ownership tool for Databricks through four distinct user experiences on Google Cloud.
Cloud Spanner GeminiAutonomous Hospital Operations with DeepMind AlphaEvolve, Cloud Spanner Graph, and Gemini - Optimizing Emergency Department Patient Flow and Clinician Workload via LLM Evolutionary Code Synthesis.
Data Analytics Gemini Official Blog PartnersHow Box is unlocking multimodal enterprise agents with Gemini Embeddings 2 - The Box Agentic Platform is designed to deliver next-generation capabilities that can handle the vast universe of digital content through multimodal AI.
Agents Official BlogHow agents can delegate better - New research shows how delegation involves intelligence: adaptive negotiations, aligning on strict rules, contracts, and security guardrails. We’ll share four principles that emerged from our work, and how you might apply them to your own workflows.
ADK AI Go Java Python TypescriptBuild zero-trust AI agents with Google's Agent Development Kit - Building autonomous AI agents that mutate production state requires moving beyond soft system prompts to a robust zero-trust architecture. To secure Google Agent Development Kit (ADK) workflows against prompt injections and malicious execution, developers must implement hardware-backed cryptographic signatures for database writes, kernel-level sandboxing with gVisor for dynamic code, and deterministic semantic gateways for I/O validation. By enforcing these hard security boundaries at the infrastructure level, you can safely deploy multi-tool AI agents without risking unauthorized data manipulation or server compromise.
Generative AI Vertex AI SearchBillion-scale vector search in GCP: The mathematics of ScaNN, HNSW, and anisotropic quantization - This article provides a deep-dive into the mathematics, backend architecture, and productionization of Google Cloud's Vertex AI Vector Search. It explains how technologies like HNSW graphs and Google's ScaNN algorithm overcome the massive computational and memory challenges of searching billions of high-dimensional vectors.
Releases
AlloyDB - You can now use the Model Context Protocol (MCP) Toolbox for Databases to access AlloyDB observability features and advanced query insights directly in your IDE. AlloyDB now provides more accurate memory usage estimation, and it prevents out-of-memory (OOM) errors when you build a ScaNN four-level tree index. This feature is in Preview. This update improves the stability of index builds by enforcing memory limits and improving memory estimation under constrained conditions. For more information, see Create a ScaNN index.
Apigee UI - Bug ID Description 540008387 Developer custom attributes now save reliably in the Apigee UI Saving changes to a developer in the Apigee UI in Cloud console no longer intermittently fails to persist that developer's custom attributes. Previously, the UI reported the save as successful, but the previous attribute values reappeared when the page was reloaded. Developer updates made with the Apigee API were not affected. Bug ID Description 543626585 ServiceCallout policy can now be added in the Apigee UI Adding a ServiceCallout policy in the Apigee UI no longer leaves the Create or Add button disabled. Previously, selecting Service Callout in the Create policy or Add policy panel could display only the Name and Display name fields and omit the required HTTP target field. With the required field missing, the form never became valid, so the Create or Add button stayed disabled no matter what you entered. This affected both API proxies and shared flows. The earlier workaround of creating a placeholder policy and replacing its XML in the code editor is no longer needed. For more information, see ServiceCallout policy and Attach and configure policies in the UI.
AppEngine Standard - Support for migrating from the App Engine Images service to Cloud Run is in General Availability (GA). You can migrate your App Engine push queues to Cloud Tasks by updating the bundled services SDK. This method lets you upgrade your app without needing to modify your application code. For more information on how to migrate, see the push queues migration guide ( Preview ).
Application Integration - Missing authorization in QueryEngineTask (CVE-2026-12710) A missing authorization vulnerability ( CVE-2026-12710 ) in QueryEngineTask in Application Integration was patched on April 4, 2026, and no customer action is needed.
Assured Workloads for Goverment - The Data Boundary for Canada Controlled Goods Program (CGP) control package is now generally available.
Backup and DR Service - Beginning November 1, 2026, Backup and DR Service will automatically apply a project-level lien to any project containing a backup vault with backups protected by enforced retention. To secure project liens against unauthorized removal and manage lien deletion securely, you can configure multi-party approval using Privileged Access Manager (PAM). For more information, see Protect project liens by using Privileged Access Manager and Protect projects with liens.
Batch - The Batch Debian 11 operating system (OS) image family has reached end of development due to the end of support (EOS) for Compute Engine Debian 11 images on August 31, 2026. The last Batch Debian 11 images—any image versions with the batch-debian-11-official prefix—are only supported until August 31, 2026. Before then, migrate any job that uses a Batch Debian 11 image to a Batch Debian 12 image (or other image) as follows: For job definitions that use the batch-debian image prefix (which is the default image for jobs with any script runnables), the image that Batch automatically selects during job creation is gradually migrating to Debian 12 no later than August 31, 2026. For any jobs created before August 31, 2026, you can check whether the job uses Debian 11 or Debian 12 by describing the job. For job definitions that specify either the batch-debian-11-official image family or an image version with that prefix, specify a different image during job creation. For example, to migrate to Debian 12, specify either the batch-debian-12-official image family or an image version with that prefix. Learn more about OS images, viewing OS images, and specifying OS images.
BigQuery - The default per-project limit of user-specific reservation assignments has been increased from 10 to 100. BigQuery supports the following table-valued functions in the query editor and as part of conversational analytics to help you analyze your time series data: ML.TREND: identify the directional trajectory of your data. ML.SEASONALITY: identify repeating patterns in your data. ML.DETECT_CHANGE_POINTS: identify intervals where structural shifts occur in your data. These functions are in preview. Starting April 26, 2027, core graph processing for BigQuery Graph will be restricted to the BigQuery Enterprise and Enterprise Plus editions. Consequently, we are deprecating support for Standard edition and on-demand billing for core graph processing. Graph measures will remain available in the Enterprise and Enterprise Plus editions and for queries run using on-demand pricing. Measures are not available in Standard edition. The run_bq_command tool exposes the bq command-line tool within the Cloud CLI remote MCP server. AI agents can now execute advanced BigQuery operations, such as job scheduling, job management, and reservation management, through a managed MCP endpoint. For more information, see Use the Cloud CLI remote MCP server. This feature is in Preview.
Bigtable - You can use the allow_incomplete_view query hint in SQL queries to read data from a continuous materialized view before its initial population finishes. This feature is generally available (GA). For more information, see Read data during initial population.
Buildpacks - Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the Go community release cycle. For more information, see Runtime support schedule.
CDN - Cloud CDN supports the targeted CDN-Cache-Control HTTP response header RFC 9213. You can use this header to specify caching directives specifically for Cloud CDN edge caches without affecting browser-level caching. For details, see Cache control header precedence. Global Front End is a unified offering that simplifies billing by consolidating pricing across networking products, including Cloud CDN, global external Application Load Balancer, Google Cloud Armor, and Service Extensions, into one solution to help deliver, scale, and secure your internet-facing applications. Cloud CDN is included in the Global Front End Enterprise billing tier. This feature is available in Preview. For more information, see Global Front End.
Chronicle Security Operations - [Spotlight Feature] Event simulation for detection coverage evaluation This feature is in public preview. You can now programmatically deliver realistic threat sequences into the live ingestion pipeline using event simulation. Event simulation provides a full-funnel detection coverage evaluation framework embedded directly within Google SecOps, enabling detection engineering and SOC teams to verify the entire detection lifecycle—from UDM normalization to multi-event correlation and alerting—while preserving production SOC workflows. As a core capability of the Detection Engineering Agent (DEA) architecture, event simulation connects Google SecOps MCP tools with AI assistance (such as Gemini) to automate threat intel processing, synthetic telemetry generation, and YARA-L 2.0 rule coverage evaluation. For more information, see Use event simulation for detection coverage evaluation. [Spotlight Feature] Evaluate threat coverage and generate rules with the Detection Engineering Agent This feature is in public preview. You can now evaluate and strengthen your Google SecOps security posture against emerging threats using the Detection Engineering Agent. This AI-powered assistant helps you extract threat intelligence and automatically draft YARA-L detection rules, drastically improves time-to-value for custom security automation and accelerating risk mitigation. The agent is accessible using Model Context Protocol (MCP) tools operated by compatible AI clients (such as Google Antigravity or Claude Code). For more information, see Evaluate threat coverage with the Detection Engineering Agent. Side-by-side view on the Alerts & Detections tab in Cases This feature is in public preview. The Alerts & Detections tab in the revamped Investigation Management experience now supports a Side-by-side view layout. You can switch between the default List view and the Side-by-side view to inspect an alert or detection's detailed metadata, status, priority, creation date, and Gemini investigation insights in an adjacent side pane without navigating away from the main list. For more information, see Investigation and case management overview. [Spotlight Feature] Relative time filtering in Google SecOps This feature is in public preview. Google SecOps has updated how relative time filters calculate data ranges. You can now choose from three distinct, mathematically precise operators: Past, Previous, and Current. This change eliminates ambiguity between rolling windows and calendar-aligned periods, ensuring consistent behavior across all time units (like seconds, minutes, hours, days, weeks, months, years) and aligning SecOps dashboards with Search and other Google tools (such as Looker). For more information, see the Relative time range section of the Understand search guide.
Cloud Functions - Support for the Go 1.27 runtime is in Preview. Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the Go community release cycle. For more information, see Runtime support schedule.
Cloud NGFW - Support for the Advanced malware sandbox (WildFire) service is now restored. You can now use Advanced malware sandbox to perform deep inspection of network-routed file transfers and block zero-day malware before it reaches your workloads. Advanced malware sandbox is available in the Cloud Next Generation Firewall Enterprise tier. For more information, see Advanced malware sandbox overview and Configure Advanced malware sandbox in your network. This feature is available in Preview.
Cloud Run - Support for the Go 1.27 runtime is in Preview. Starting from Go runtime version 1.26 and later, the lifecycle support dates align more closely with the Go community release cycle. For more information, see Runtime support schedule.
Cloud Storage - If you delete your project, buckets that have soft delete enabled are now retained for a limited amount of time before being permanently deleted. If you restore a deleted project during this time period, these buckets are restored to the state that they were in when the project was deleted. For more information about soft delete and the restoration window, see Soft delete.
Cloud Trace - The following limits associated with the Cloud Trace API, cloudtrace.googleapis.com, have increased: Maximum attributes per span: 1,024 Maximum attribute value size: 65,532 bytes Maximum attribute key size: 512 bytes Maximum span name length: 1,024 bytes Maximum events per span: 256 The new limits are consistent with those supported by the Telemetry API, which implements the OpenTelemetry Protocol (OTLP). For more information, see Cloud Trace API quotas and limits.
Compute Engine - Preview: Image Builder is available in allowlist-only Preview. Image Builder is a declarative operating system (OS) image customization tool that automates the process of building, customizing, and validating custom OS images within Google Cloud by using Cloud Build. For more information about Image Builder, see About Image Builder. To onboard your project and request access, fill out the request form. Generally available: The network- and memory-optimized M4N machine series is generally available. Powered by 5th generation Intel Xeon Scalable processors (Emerald Rapids), M4N instances are purpose-built for network and block storage-intensive workloads such as: High-performance vector databases Retrieval-augmented generation (RAG) data layers Massive in-memory context caching Real-time semantic search The M4N machine series delivers the highest I/O performance available in Compute Engine, supporting up to 400 Gbps of network bandwidth. M4N also offers leading block storage performance with Hyperdisk Extreme that scales up to 25 GiB/s of bandwidth and 1M IOPS. M4N instances are available in predefined machine shapes, ranging in size from 16 to 224 vCPUs and up to 5,952 GB of DDR5 memory.
Contact Center AI Platform - Full details on the release page.
Database Migration Service - Database Migration Service for MySQL homogeneous migrations now supports MySQL version 9.7. For more information, see Supported source and destination databases.
Dataflow - Dataflow job builder now supports Delta Lake tables as a source. You can now import existing Delta Lake tables from Cloud Storage ( gs:// BUCKET_NAME ) directly into Lakehouse for Apache Iceberg using Dataflow's job builder UI without writing code. For more information, see Import Delta Lake tables into Lakehouse using Dataflow.
Dataform - You can now use the Dataform remote Model Context Protocol (MCP) server to manage data transformation workflows through AI agents. This feature is generally available (GA).
Gemini - Credits for the first month of Gemini Code Assist usage are discontinued. Customers currently receiving these credits are unaffected by this change. Previously, these credits had been available to new customers with billing accounts if they had never had a Gemini Code Assist subscription.
Google Cloud Armor - Global Front End is a unified offering that simplifies billing by consolidating pricing across networking products. Cloud Armor is included in the Global Front End Enterprise billing tier. Enabling Global Front End Enterprise in a project enables specific Cloud Armor Enterprise features for your global external Application Load Balancers. For more information, see Global Front End.This feature is available in Preview.
Load Balancing - Global Front End combines global external Application Load Balancers, Google Cloud Armor, Cloud CDN, and Service Extensions into one solution to help deliver, scale, and secure your internet-facing applications. For more information, see Global Front End. This feature is available in Preview.
Looker - Looker's Continuous Integration is based on the legacy standalone Spectacles service. Looker will continue to integrate and evolve the Spectacles features into Looker's Continuous Integration, and the legacy standalone Spectacles service itself will be discontinued starting November 30, 2026. Existing Spectacles customers will receive an email with details. If you have any questions or require assistance, please contact us at [email protected]. The latest versions in the Looker (Google Cloud core) release channels are beginning deployment as follows: Latest version in the Rapid channel: Looker 26.14 Latest version in the Regular channel: Looker 26.12 Latest version in the No Channel channel: Looker 26.14
NetApp - Google Cloud NetApp Volumes is now Canada Controlled Goods (CCG) compliant for the Standard, Premium, and Extreme service levels. For more information, see Compliance. Google Cloud NetApp Volumes is now Canada Controlled Goods (CCG) compliant for the Standard, Premium, and Extreme service levels. For more information, see compliance.
Sensitive Data Protection - Image scanning is available in the following regions: europe-north1 us-central1 For more information, see Locations that support image scanning.
Service Mesh - The guidance for using proxy image types ( default and distroless ) with Managed Cloud Service Mesh has been updated: Directly onboarded clusters using the TRAFFIC_DIRECTOR implementation use distroless proxy images by default, and other image types are not supported. Migrated clusters (migrated from ISTIOD to TRAFFIC_DIRECTOR ) default to default images, but can opt in to distroless images via MeshConfig or the sidecar.istio.io/proxyImageType: distroless Pod annotation. For more information, see Distroless proxy images and Identify the proxy image type used in the cluster.
Virtual Private Cloud - General Availability: You can use Private Service Connect endpoints and backends to access multi-regional service endpoints such as storage.us.rep.googleapis.com.