The following release notes cover the most recent changes over the last 60 days. For a comprehensive list of product-specific release notes, see the individual product release note pages.
You can also see and filter all release notes in the Cloud de Confiance console or you can programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
September 16, 2026
Virtual Private CloudGeneral Availability: You can add Dynamic NICs to the same VPC network used by other network interfaces of a Compute Engine instance. For more information, see Multiple network interfaces.
General Availability: VPC Flow Logs supports logging for App Engine resources that are configured with Direct VPC egress. For more information, see Serverless flows and ServerlessDetails field format.
General Availability: VPC Flow Logs adds the following metadata annotations for Private Service Connect:
src_psc_interfaceanddest_psc_interfacepsc.consumer_connectionpsc.psc_endpoint.namepsc.psc_attachment.name
For more information, see Record format.
August 31, 2026
Virtual Private CloudGeneral Availability: You can create Compute Engine instances that have multiple virtual network interfaces (vNICs) in the same VPC network. For more information, see Multiple network interfaces in the same VPC network.
August 28, 2026
Cloud RunCloud Run is now available in your Google Cloud Dedicated universe. For more information, see the Product overview.
August 27, 2026
Google Cloud ArmorCloud Armor supports advanced match conditions to include attributes for inspecting request body content and parameters in Preview. This lets you write custom CEL rules to filter traffic based on raw body content, structured data (JSON, Form Data, GraphQL), and query parameters. For more information, see Configure custom rules language attributes.
General Availability: VPC Flow Logs generates log records for dropped traffic. For more information, see Records for dropped traffic.
General Availability: You can reserve static external IPv6 addresses from
bring your own IP addresses (BYOIP) sub-prefixes that are in
EXTERNAL_IPV6_FORWARDING_RULE_CREATION mode.
You can assign these addresses to forwarding rules for external passthrough Network Load Balancers and external protocol forwarding. You can also promote ephemeral IPv6 BYOIP addresses that are used by external forwarding rules to reserved static IP addresses.
For more information, see Create external forwarding rules.
August 24, 2026
Cloud Key Management ServiceCloud KMS supports deleting key rings in General Availability.
For more information about deleting Cloud KMS resources, see Delete Cloud KMS resources.
August 19, 2026
Google Cloud ArmorGlobal Front End is a unified offering that simplifies billing by consolidating pricing across networking products. Cloud Armor is included in the Global Front End Enterprise billing tier. Enabling Global Front End Enterprise in a project enables specific Cloud Armor Enterprise features for your global external Application Load Balancers. For more information, see Global Front End.This feature is available in Preview.
August 17, 2026
Cloud StorageIf you delete your project, buckets that have soft delete enabled are now retained for a limited amount of time before being permanently deleted. If you restore a deleted project during this time period, these buckets are restored to the state that they were in when the project was deleted.
For more information about soft delete and the restoration window, see Soft delete.
August 12, 2026
Network Intelligence CenterConnectivity Tests supports using a Cloud Run job as a source endpoint for connectivity testing.
For more information, see Test from a Cloud Run job to a destination.
August 07, 2026
Secret ManagerSecret Manager is generally available in your Google Cloud Dedicated universe.
General Availability: You can use Private Service Connect endpoints to access global Google APIs. For more information, see About accessing Google APIs through endpoints.
August 06, 2026
Access TransparencyAccess Transparency is generally available in Google Cloud Dedicated universe.
Preview: Cloud KMS supports quantum-safe key import. You can use the following quantum-safe import methods:
HPKE_KEM_XWING_HKDF_SHA256_AES_256_GCMHPKE_KEM_ML_KEM_768_HKDF_SHA256_AES_256_GCMHPKE_KEM_ML_KEM_1024_HKDF_SHA256_AES_256_GCM
For more information about quantum-safe key import, see Quantum-safe key import.
August 04, 2026
Cloud SQL for MySQLCloud SQL for MySQL supports resource groups. MySQL resource groups let you manage resource allocation for different workloads on your Cloud SQL for MySQL instance. By using resource groups, you can prevent less important workloads from consuming excessive CPU or memory resources.
To use MySQL resource groups, you must have maintenance version MYSQL_VERSION.R20260320.00_20 or later installed on your instance.
For more information, see Manage CPU allocation with MySQL resource groups.
July 31, 2026
Cloud SQL for MySQLStarting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
Starting on August 1, 2026, when you create or clone a Cloud SQL instance enabled with Private Service Connect, or when you enable Private Service Connect for an existing instance, then connection reconciliation behavior is enabled by default and can't be disabled.
When you remove a project from the list of allowed projects, all existing Private Service Connect connections from the removed project are immediately closed (reconciled). This means that applications using Private Service Connect endpoints in those removed projects can't continue to connect to the Cloud SQL instance using those endpoints.
For more information, see Allowed Private Service Connect projects.
July 30, 2026
Virtual Private CloudGeneral Availability: You can use the Resolve subnet mask setting on a
subnet to configure all attached Compute Engine instances with the same netmask
as the subnet (instead of /32). Configuring larger instance netmasks lets
compute instances discover the MAC addresses of other machines within the same
subnet and directly communicate with them by using destination MAC addresses.
For more information, see Compute instance netmasks.
July 29, 2026
Cloud SQL for MySQLCloud SQL for MySQL now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.
For more information, see Re-encrypt an existing CMEK-enabled instance or replica.
Cloud SQL for PostgreSQL now supports significantly faster re-encryption of instances and replicas protected by customer-managed encryption keys (CMEKs), and re-encryption now completes with zero downtime. The steps to re-encrypt your instances and replicas are unchanged, but the operation now re-encrypts the underlying disks in-place, without creating re-encryption backups.
For more information, see Re-encrypt an existing CMEK-enabled instance or replica.
July 24, 2026
Compute EngineGenerally available: A3 High machine types with 1, 2, 4, or 8 NVIDIA H100 GPUs attached. These machine types are ideal for high performance computing (HPC) and machine learning (ML) workloads such as model inference, model training and fine tuning, and simulations.
To get started, see the Accelerator-optimized machine family guide.