Welcome to issue #521 September 21st, 2026

News

FinOpsFirebase

Introducing Firebase spend caps - Firebase has introduced new spend caps for key services like the Gemini API and Cloud Functions to help developers prevent unexpected cloud bills. This new feature provides granular cost control by automatically pausing services when budgets are reached and sending multi-stage email alerts.

BigQueryData AnalyticsOfficial Blog

Accelerating the borderless Lakehouse: Announcing preview of cross-cloud caching - In the borderless Lakehouse, cross-cloud caching reduces data transfers, and BigQuery cross-cloud connections enables querying data in other clouds.

Cloud DataflowData AnalyticsGPUOfficial Blog

Announcing Pause/Resume and NVIDIA RTX PRO 6000 Blackwell GPU support in Dataflow - Recent features and capabilities in Dataflow improve developer productivity and accelerate batch and streaming AI workloads.

Agent SubstrateGoogle Kubernetes EngineOfficial Blog

Agent Substrate brings high-density, scalable, trusted infrastructure to GKE - Agent Substrate is an open source, high-density agent runtime that can run scale to millions of sandboxes on a single cluster.

AIGemini Enterprise Agent PlatformMonitoring

Agent Anomaly Detection, now in Private Preview on the Gemini Enterprise Agent Platform - Agent Anomaly Detection is a new, out-of-band oversight layer for the Gemini Enterprise Agent Platform that analyzes OpenTelemetry traces and tool calls to catch behavioral risks without adding runtime latency to live requests. It utilizes a multi-tiered detection pipeline—combining lightweight statistical scanning with deep LLM-based reasoning—to identify logical anomalies and policy violations grounded in the OWASP Agentic Top 10.

Cloud FilestoreOfficial Blog

Introducing Filestore agent volumes: fully managed storage for agent workspaces - Filestore agent volumes provide secure, fully managed, elastic file storage that’s purpose-built for AI agent workspaces.

Official BlogSecurity

Introducing new session management tools with native, granular controls - New Google Cloud session controls are deeply integrated and a granular feature of Context-Aware Access. Here’s what you need to know.

Compute EngineDatabasesOfficial Blog

M4N VM family, now GA: Highest per-core IOPS and throughput for I/O and memory-bound workloads - The M4N machine series is now GA, providing high per-core IOPS and throughput, and over 20% TCO reduction for Oracle databases.

Cloud SQLDatabasesOfficial Blog

Announcing Native BM25 Ranking in AlloyDB and Cloud SQL - A native BM25 index in AlloyDB and Cloud SQL provides full-text retrieval without having to provision, manage, or pay for separate systems.

Official BlogQuadrant

Google is a leader in The Forrester Wave™: Public Cloud Platforms, Q3 2026 - Google was named a Leader in the latest Forrester Wave™: Public Cloud Platforms, Q3 2026 report, showing the value of codesigned AI infrastructure.

Official Blog

Google named a Leader in the External Threat Intelligence Service Forrester Wave™ - We are proud to announce that Forrester has named Google a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026.

Official BlogPublic Sector

Reimagining service delivery in the agentic era with Google Public Sector - Discover how state and local agencies use Google Cloud AI to break data silos and modernize public services. Join us at the GPS Summit Oct 20.

Articles, Tutorials

Infrastructure, Networking, Security, Kubernetes

CISO Official Blog

Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses - AI is driving 3 structural shifts in the threat landscape that CISOs must address. Learn about Google’s visibility into them — and how we’re solving them.

Agents GCP Experience Google Kubernetes Engine Official Blog

For SeaVerse, GKE Agent Sandbox reduces infrastructure costs by 60% - GKE Agent Sandbox gave SeaVerse the strong isolation and performance it needed for its agent-based gaming platform, while helping it save on costs.

Google Kubernetes Engine

Mastering fleet-wide governance on GKE using fleet level OPA - This article explores how platform engineering teams can achieve centralized governance and security across multiple Google Kubernetes Engine (GKE) clusters using GKE Policy Controller. It compares the enterprise-ready tool with open-source OPA Gatekeeper and highlights practical guardrails, such as image registry whitelisting and resource limits, to maintain compliance at scale.

Config Connector Google Kubernetes Engine GPU Kubernetes

How We Built GPU Failover on GKE Without Giving Up Infrastructure Control - This article explores how to implement priority-based GPU failover on Google Kubernetes Engine (GKE) while maintaining centralized infrastructure control using Config Connector. It demonstrates how GKE Custom ComputeClasses can be configured to enable automatic fallback between approved node pools during capacity shortages without allowing uncontrolled node pool creation.

Google Kubernetes Engine GPU

Sharing One Physical GPU Across Multiple Pods on GKE with Dynamic Resource Allocation - This article explores using Kubernetes Dynamic Resource Allocation (DRA) on Google Kubernetes Engine to enable multiple Pods to share a single physical NVIDIA GPU.

Google Kubernetes Engine Kubernetes

Exit Through the Wrong Pipe - This article explores why Google Kubernetes Engine (GKE) incorrectly labels routine, healthy system logs as errors due to a mismatch between how Kubernetes logging libraries output data and how Google Cloud Logging ingests streams. It examines the historical design choices behind this behavior, the hidden costs of managing false-positive alerts, and practical workarounds for developers navigating this platform quirk.

IAM Security

Killing the “Keys to the Kingdom”: Automated Just-In-Time Policy Elevator on Google Cloud - This article introduces an open-source Just-In-Time (JIT) access broker designed to eliminate permanent standing high-privilege roles on Google Cloud. It explains how the system uses project-scoped IAM CEL conditions, peer approvals, and an event-driven watchdog to grant secure, short-lived permissions.

Security

New to Google SecOps: Building Your First Search with SQL Pipes - Google Security Operations now supports SQL search alongside traditional YARA-L, offering users an alternative way to query threat data. Specifically, the platform supports SQL pipe syntax, which provides an intuitive, top-down approach similar to SPL and KQL for filtering and aggregating security events.

App Development, Serverless, Databases, DevOps

Event Official Blog

The DevFest Community Workshop Experience: Building Real Agents Together - This article explores the new Google Cloud DevFest community workshops, which ditch traditional copy-paste coding tutorials in favor of an immersive "Workbench" model focused on core architectural concepts and mental frameworks.

Gemini Google Cloud Consulting Official Blog

How to upskill enterprise AI builders by using daily micro habits - With the Build with Gemini event series underway, Google Cloud Consulting is seeing more leaders rethink AI enablement by building quick, daily practice into their teams' routines. In this post, we'll walk through a four-pillar approach and the lessons from our global developer challenges to share what micro-habit upskilling looks like.

Agents Databases MCP

Launching MCP Apps in Toolbox - MCP Toolbox for Databases now includes official support for the MCP Apps extension.

BigQuery Cloud Spanner Data Analytics Databases Official Blog

Scaling Telco Autonomy: Leveraging GNNs with Distributed GraphFlow - Learn how Distributed GraphFlow scales GNNs for Autonomous Network Operations. Simplify your end-to-end GNN modeling with Google’s new open-source library.

Google Cloud Consulting Official Blog SRE

Best practices for handling cloud reliability incidents - Incident handling primer to help Google Cloud Platform customers design and practice reliability incident response and minimize business impact.

AlloyDB Databases MCP Official Blog Startups

How a solo founder runs a five-continent tender platform on AlloyDB and MCP - How Lucius AI runs a 210,000-tender platform on AlloyDB for PostgreSQL with one operator: ScaNN search 47x faster, database ops delegated over MCP.

Agents Official Blog

Changing the game: How Google uses agentic AI to secure hundreds of millions of lines of code - We use AI agents to scan every code change that we deploy onto our infrastructure, preventing vulnerabilities from reaching production.

AI DevOps

Why client SDK generation belongs in the open - Google has partnered with Speakeasy to open-source their OpenAPI code generation suite under the AGPLv3 license, a strategic move prompted by the sudden shutdown of Google's previous proprietary SDK provider. The newly open-sourced suite equips developers with deterministic, multi-language SDK generators that natively support strict typing and SSE streaming, alongside tools for compiling agent-native CLIs and documentation MCP servers.

AI Data Science Databases

From Choice Paralysis to Day 0 Provisioning: Meet the Google Cloud Database Onboarding Agent & Skill - This article introduces the Google Cloud Database Onboarding Agent and Skill, a tool designed to eliminate the complexity of selecting and provisioning the right database for new applications.

Cloud Run Infrastructure

What I Learned About Cloud Run Instances - This article explores Google Cloud Run's new "Instances" feature, explaining how it bridges the gap for workloads requiring long-lived connections, such as AI agents or personal automation tools.

Big Data, Analytics, ML&AI

BigQuery Data Science Paywall

The $5,000 GA4 BigQuery Unnesting Mistake: Scalar Subqueries vs. CROSS JOIN - If your Google Cloud bill is exploding, unpacking repeated records before projecting columns is almost certainly the culprit.

Airflow Cloud Composer Data Analytics Official Blog

The future of orchestration: Pine59’s journey to Airflow 3 on Google Cloud - Pine59 decided to modernize its monorepo to improve its MLOps capabilities, developer workflow, and pipeline speed.

AI Cloud Pub/Sub Data Analytics Machine Learning

Pub/Sub AI Bytes: Part2 — Real-time model telemetry ingestion at scale - Emerging AI architecture pattern to show how AI-native enterprises ingest massive volumes of real-time telemetry data at scale!

BigQuery

Arrays in BigQuery: what they are and how to get data out of them - This article explores how arrays function in Google Cloud's BigQuery, offering a practical guide to handling complex data structures like GA4 exports. It breaks down essential techniques for querying nested data, including using UNNEST, avoiding common pitfalls with SAFE_OFFSET, and leveraging new shorthand functions like ARRAY_FIRST and ARRAY_AGG.

Apache Iceberg BigQuery

How considering an Iceberg migration made me rethink BigQuery costs — Platforming Data - An evaluation of a potential Apache Iceberg migration revealed unexpected cost and performance trade-offs in Google Cloud's BigQuery, such as faster execution times that paradoxically required higher compute consumption. This discovery prompted a comprehensive reassessment of BigQuery pricing models, prompting a deeper look at how storage billing, query execution, and capacity pricing interact.

BigQuery dbt

Concurrent Microbatch Support Exists for BigQuery dbt (You’re Welcome) - This article highlights the newly added, yet unannounced, support for dbt’s concurrent microbatch strategy within Google Cloud's BigQuery. It explains how enabling this feature allows data engineers to run large backfill jobs significantly faster by processing multiple incremental batches in parallel.

BigQuery Data Analytics Official Blog

Agent-ready analytics: Unlocking insights with BigQuery augmented analytics - BigQuery augmented analytics Table-Valued Functions (TVFs) automate insight discovery and pattern explanation using AI, ML and statistical methods.

BigQuery

Clickstream Data Validation: 5 Ways to Make It Reliable - Based on real clickstream data scenarios from e-commerce and travel platforms.

Agents BigQuery Data Analytics

How to Build a Data Agent in BigQuery Conversational Analytics - This article provides a practical, step-by-step guide to building a custom Data Agent using Google Cloud's BigQuery Conversational Analytics. It covers essential configuration steps—including setting up knowledge sources, business glossaries, and verified queries—to ensure your AI assistant delivers accurate and reliable data insights.

GCP Experience Official Blog Telecommunications

How Orange uses agents to make FinOps everyone's responsibility - FinOps is a business change problem. Orange harnessed specialized agents to overcome the usual FinOps hurdles to accelerate AI adoption and ROI.

AI Gemini Enterprise Agent Platform Go Java Python Typescript

Build zero-trust AI agents that judge intent, not just syntax - This blog post explores how to transition AI agents from static, build-time security controls to dynamic runtime governance using the Gemini Enterprise Agent Platform. It highlights three primary managed defenses: Model Armor for screening edge prompts, Semantic Governance Policies for evaluating tool intent against business rules, and Agent Anomaly Detection for catching multi-turn exploits.

Agents BigQuery

From manual to autonomous: A blueprint for agentic process automation on GCP - This article explores a multi-agent Google Cloud architecture that transforms enterprise customer value management into an autonomous analytics engine capable of delivering actionable insights in minutes.

Compute Engine JAX TPU

Zero-infrastructure managed XProf: Profiling ML workloads on Cloud TPU with ML Diagnostics - This article provides a step-by-step walkthrough on using the Google Cloud ML Diagnostics SDK to monitor and profile JAX machine learning workloads running on Cloud TPU VMs. It explains how to instrument training scripts to stream real-time hardware telemetry and capture XProf performance traces directly into the Google Cloud console.

ADK Gemini MCP

Building enterprise AI agents with ADK and the Gmail MCP Server - This article explains how to build production-grade, autonomous Gmail AI agents using the Google Agent Development Kit and managed Model Context Protocol endpoints. It provides a comprehensive technical blueprint comparing user-consent and domain-wide delegation authentication architectures, complete with token caching strategies and deployment guidelines for Google Cloud Run.

AI

Data Agent Kit: What It Does, How It Works, and How to Use It Safely. - A practitioner’s tour of Google Cloud’s Data Agent Kit: how MCP servers and agent skills work together, real prompts from start to finish….

Agents

Slot-Filling Framework: Guide to Building Deterministic Agents on Google Cloud CXAS - What if your AI agent could converse with the warmth of a human while executing business logic with 100% deterministic responses?

Releases

Apigee Hybrid - Full details on the release page.

Artifact Registry - Artifact Registry support for managing Conda packages with Artifact Registry repositories is in Preview. For more information, see Get started with Conda packages.

Backup and DR Service - You can now monitor restore jobs for Filestore instances directly from the Backup and DR Jobs page in the Google Cloud console. When you trigger a restore on a Filestore instance, Backup and DR automatically tracks the job progress and status. For more information, see Restore a Filestore instance from a backup vault and Monitor backup and restore jobs in Google Cloud console. You can now use auto-protection policies and resource labels to automatically protect Compute Engine instances and Persistent Disks at scale in Backup and DR. This feature allows you to automatically assign a backup plan to qualifying resources across projects based on user-defined labels. This feature is in Preview. For more information, see Automate resource protection.

Batch - A workaround has been added for the known issue that jobs might fail when specifying Compute Engine (or custom) VM OS images with outdated kernels.

BigQuery - An updated version of the Simba ODBC driver for BigQuery is now available. You can now include a WHERE clause inside of an aggregate function call to filter your aggregate function input using a boolean expression. This feature is in Preview. Metadata for BigQuery Graph is automatically ingested and searchable in Knowledge Catalog. This feature is available in preview. You can use the migration lineage service to visualize the data flow and connections in your source database and help you plan a BigQuery data warehouse migration. This feature is in Preview. You can add unit tests to pipelines to validate your SQL transformation logic against mock datasets. Unit tests for pipelines are generally available (GA).

Bigtable - You can use the Google Cloud console to create, list, and query parameterized views for your Bigtable instances. You can also configure view parameters and run queries in Bigtable Studio. This feature is generally available (GA). For more information, see Create and manage parameterized views.

Carbon Footprint - Full details on the release page.

Chronicle - MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC` feeds are being removed The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI. Grok filter match_all option in parser syntax The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match. For more information, see Parser syntax reference.

Chronicle Security Operations - [Spotlight Feature] GoogleSQL query support in Search This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and powerful industry-standard alternative to YARA-L 2.0. GoogleSQL is optimized for broad data exploration, statistical aggregation, and deep-dive ad hoc investigations. You can query telemetry tables including but not limited to UDM events, entity graphs, detection rules, and case management data—using either standard declarative SQL or the linear, sequential Piped SQL syntax. For more information, see Get started with GoogleSQL. MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC` feeds are being removed The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI. Grok filter match_all option in parser syntax The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match. For more information, see Parser syntax reference. Resizable side panels in the Investigation Management experience You can now dynamically resize the Case preview and Alert and detection preview side panels in the revamped Investigation Management experience in Google SecOps. You can adjust the panel width using your mouse or keyboard shortcuts to view detailed telemetry, parsed UDM records, and raw logs without navigating away from your main case queue. To explore the complete triage workflow, see Investigation and case management overview.

Cloud Asset Inventory - The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs. Network Management API networkmanagement.googleapis.com/VpcFlowLogsConfig The following resource type is publicly available through the ExportAssets, ListAssets, BatchGetAssetsHistory, QueryAssets, and Feed APIs. Cloud TPU API tpu.googleapis.com/QueuedResource

Cloud Filestore - Small capacity Filestore instances for the Regional service tier are generally available (GA). Small capacity instances start at 100 GiB and scale in 1 GiB increments, providing an option for development, testing, and applications with low traffic or basic storage needs. For more information, see Small capacity instances.

Cloud Logging - Starting with version 2.71.0, you can use an Ops Agent configuration option to export your metrics, logs, and traces by using the OpenTelemetry-based Telemetry API rather than by using the Cloud Monitoring API, Logging API, or Trace API For more information, see Use the Telemetry API.

Cloud Monitoring - Starting with version 2.71.0, you can use an Ops Agent configuration option to export your metrics, logs, and traces by using the OpenTelemetry-based Telemetry API rather than by using the Cloud Monitoring API, Logging API, or Trace API For more information, see Use the Telemetry API.

Cloud SQL MySQL - Cloud SQL for MySQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time. For more information, see Use advanced disaster recovery (DR).

Cloud SQL Postgres - You can use the pg_textsearch extension in Cloud SQL for PostgreSQL to perform full-text search using the industry-standard BM25 (Best Matching 25) scoring algorithm for highly accurate relevance scoring. This extension requires PostgreSQL 17 or later and is supported on PostgreSQL release R20260712.01_06 or later. For more information, see Full-text search using pg_textsearch. Cloud SQL for PostgreSQL now automatically enables point-in-time recovery (PITR) in a separate, asynchronous operation after disaster recovery (DR) switchover and replica failover operations complete. Because PITR enablement no longer blocks switchover and replica failover, these operations complete faster, helping you reduce your recovery time. For more information, see Use advanced disaster recovery (DR).

Cloud SQL SQL Server - Beginning April 12, 2027, you won't be able to create new instances of Cloud SQL for SQL Server 2017. Starting on October 13, 2027, SQL Server 2017 will reach end of life (EOL) and Microsoft will stop releasing security updates. Cloud SQL for SQL Server will stop supporting SQL Server 2017 after this date. For more information, see Database versions and version policies.

Cloud Scheduler - Cloud Scheduler is available in the following location: asia-southeast3 (Bangkok, Thailand)

Cloud Spanner - Spanner queues are generally available (GA). Spanner queues provide transactional messaging to help you manage asynchronous work. The feature pairs this capability with the scalability and reliability of Spanner, letting you build event-driven applications. For more information, see the Spanner queues overview.

Compute Engine - Preview: You can create regional disks, including Hyperdisk Balanced High Availability volumes, from custom and public OS images. For more information, see Create and manage regional disks. Public preview: Network-optimized C4N machine type with 375 GiB to 12,000 GiB of attached Titanium SSD are now available in Preview. You don't have to request allowlist approval. For more information, see C4N machine series. Generally available: The storage-optimized Z4D machine series is generally available for Compute Engine. Powered by AMD EPYC Turin processors and Titanium offload processors, Z4D instances are purpose-built for low core usage and high storage density workloads such as: SQL, NoSQL, and vector databases Data analytics and data warehouses Search Parallel file systems for AI/ML The Z4D machine series delivers up to 3 TB of memory and 42,000 GiB of local Titanium SSD capacity. Z4D also supports up to 400 Gbps of network bandwidth using two physical NICs. Z4D instances are available in predefined standardlssd and highlssd machine shapes. For more information, see Storage-optimized machine family.

Contact Center AI Platform - Full details on the release page.

Container Registry - Artifact Registry support for managing Conda packages with Artifact Registry repositories is in Preview. For more information, see Get started with Conda packages.

Dataform - You can use unit tests to test Dataform actions against mock data with an expected result set. Dataform unit tests are generally available (GA).

Dataplex - Metadata for BigQuery Graph is now automatically ingested and searchable in Knowledge Catalog. This feature is available in preview. For more information, see Knowledge Catalog overview.

Datastream - Datastream now supports MongoDB extended JSON canonical mode as the default format for new streams from MongoDB sources to BigQuery destinations. Canonical mode provides higher data fidelity by explicitly labeling every BSON type to prevent precision loss during data exchange. For more information, see the following: Stream data from MongoDB databases MongoDB data types in BigQuery

Google Cloud Armor - Cloud Armor managed rulesets protect your backend services and APIs from a wide range of web application threats using threat signatures which are automatically kept up-to-date. For more information, see Managed rules overview. This feature is available in Preview.

Load Balancing - Managed workload identity for backend mTLS is generally available for the following Application Load Balancers: Global external Application Load Balancers Regional external Application Load Balancers Cross-region internal Application Load Balancers Regional internal Application Load Balancers The key benefits are as follows: Streamline certificate management: Automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager. Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance. Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments. For more information, see Backend mTLS with managed workload identity overview

Looker - Full details on the release page.

NetApp - Effective September 15, 2026, you can't create new Flex File storage pools, but existing pools remain supported. Support for the Flex File service level of Google Cloud NetApp Volumes ends on June 15, 2027. You must migrate your data from Flex File to the Flex Unified service level. For more information, see Migration to Flex Unified service level. Organization Policy Service custom constraints are available for Google Cloud NetApp Volumes. You can use custom constraints to control how NetApp Volumes is used in your organization. For example, you can restrict storage pool or volume capacity, or enforce that storage pools are created only with Premium or Extreme service levels. For more information, see Custom organization policy constraints.

Network Intelligence Center - When adding a new Google Cloud Compute Engine, container, or VM Monitoring Point, Cloud Network Insights lets you generate Google Cloud CLI commands in the Google Cloud console to download Monitoring Point installation bundles.

Policy Intelligence - Policy Troubleshooter now supports troubleshooting access for agent identities. You can troubleshoot IAM allow policies, deny policies, and principal access boundary policies for agents acting under their own authority by entering the agent's principal identifier or by troubleshooting with an error ID from an access denial event. To learn more, see Troubleshooting access.

Secret Manager - Parameter Manager supports CRC32C checksums to verify data integrity when you add or access parameter versions. For more information, see Data integrity assurance.

Secure Source Manager - Secure Source Manager webhooks now support Pull request comment trigger events. You can configure webhooks to trigger notifications whenever a comment is added, edited, or deleted on a pull request. For more information, see the Pull request comment event payload in the Webhooks overview.

Security Command Center - Data Security Posture Management is deprecated. It will be shut down on February 1, 2027. Learn more about the controls and alternative detection capabilities. You can use the following MCP server endpoints to enable LLM agents to perform investigative and management tasks in Security Command Center. Security Command Center Security Command Center Management This feature is in Preview.

Virtual Private Cloud - General Availability: VPC Flow Logs adds the following metadata annotations for Private Service Connect: src_psc_interface and dest_psc_interface psc.consumer_connection psc.psc_endpoint.name psc.psc_attachment.name For more information, see Record format. General Availability: VPC Flow Logs supports logging for App Engine resources that are configured with Direct VPC egress. For more information, see Serverless flows and ServerlessDetails field format. General Availability: You can add Dynamic NICs to the same VPC network used by other network interfaces of a Compute Engine instance. For more information, see Multiple network interfaces.

Workstation - Cloud Workstations supports customizing provisioned IOPS and throughput for Hyperdisk Balanced High Availability disks. This customization feature is in Preview.