Home Resume
Homeβ€Ί Blogβ€Ί GCP Weekly Intelligence #1 - 10-14 August 2026
GCP Weekly Intelligence GCP

Everything Google Cloud Shipped This Week, Ranked

169 distinct changes across five working days, of which 80 are substantive and the rest are routine image and version notes. The ones that matter are explained here, two carry deadlines, and everything is accounted for.

Verified against current vendor documentation on 14 August 2026. Pricing, limits and API behaviour were checked against the official docs on that date. Cloud services change fast — if you are reading this much later, treat the specifics as a starting point and re-check the linked sources.
GCP Weekly Intelligence Β· 10–14 August 2026

The week in one paragraph

A mid-sized week with two things in it that have dates attached, which is unusual and is where to start. App Engine begins forcing TLS 1.2 and later, and the opt-out closes at the end of this month. Cloud Hub's App Topology API moves to usage-based billing on 15 September. Everything else is additive: flexible committed use discounts finally reach the G2 and G4 GPU families, Cloud SQL for MySQL 9.7 goes GA, Security Command Center's Vulnerability Assessment goes GA, and Sensitive Data Protection learns to recognise Anthropic, Gemini and OpenAI API keys everywhere. Volume was concentrated on Tuesday, which alone carried 82 of the week's 176 notes.

Two dated changes, in order of how soon they bite

End of August 2026 β€” App Engine opts your application into TLS 1.2 and later. You can opt out until the end of the month, and then you cannot.

15 September 2026 β€” the Cloud Hub App Topology API transitions to usage-based billing, with a daily free allotment. If you poll it, this is now a line on your bill.

Cost and commitments

Flexible CUDs now cover G2 and G4. Compute flexible committed use discounts became generally available for the G2 and G4 GPU accelerator-optimized machine series. This is the week's most consequential item for anyone with steady GPU spend: flexible CUDs commit to an hourly spend rather than to a specific machine shape, so a workload that moves between GPU types keeps the discount. Until now the GPU families were the gap in that story.

Cloud Hub App Topology moves to usage-based billing on 15 September. A daily free data allotment is included. The change is small in absolute terms and easy to miss entirely, which is exactly why it belongs at the top rather than in a footnote.

Carbon Footprint changed its methodology. Google is now using Granular Certificates purchased from the marketplace to match energy consumption. If you report cloud emissions to anyone, the numbers underneath your report moved this week.

Security and identity

Sensitive Data Protection now detects LLM API keys in all regions. The ANTHROPIC_API_KEY, GEMINI_API_KEY and OPENAI_API_KEY infoType detectors are available everywhere. This is the cheapest win in the week: model API keys have been leaking into logs, prompts and source repositories for two years, and there is now a built-in detector for them rather than a custom regex somebody has to maintain.

Security Command Center: Vulnerability Assessment for Google Cloud went GA, and its integration with Application Design Center for application lifecycle security assessments went GA alongside it. AI Protection also gained data residency in Saudi Arabia across all Security Command Center tiers.

VPC Service Controls got a recommender, in Preview. It suggests optimisations to existing service perimeters. Perimeters are the control on Google Cloud that is most often misconfigured into either uselessness or an outage, and until now there was no tooling that would tell you which one yours was closer to.

IAM added Organization Policy custom constraints for Agent Identity resources, giving field-level control over agent identities β€” governance arriving alongside the agent tooling rather than a year behind it. Separately, the console workflow for creating workforce identity pool providers changed: the provider is now created before you finish configuring it, which affects anyone with a written runbook for that screen.

Data and analytics

Cloud SQL for MySQL 9.7 is generally available. The one item this week that most estates will eventually have to act on, and the one with the longest tail of testing behind it.

Bigtable added parameterized views, which filter data ranges for logical views based on application context and are explicitly positioned as mitigating SQL injection β€” a notable framing for a NoSQL store that now speaks enough SQL to have the problem. It also added a CLUSTER_ATTRIBUTE() filter to confine continuous materialized view processing to specific clusters.

Memorystore for Valkey made migration from self-managed Redis and Valkey on Google Cloud generally available, and added basic token authentication in Preview.

Firestore and Firestore in Datastore mode reached asia-southeast3 (Bangkok), and Spanner made dynamic channel pooling GA in the Go and Java clients, which removes a class of gRPC channel performance problem people used to solve by hand. Dataform workflows and BigQuery pipelines gained automated metadata enrichment.

Compute, containers and runtimes

App Engine's TLS change is the deadline item. Starting this month App Engine opts applications into TLS 1.2 and later, across both standard and flexible environments and every runtime β€” the same note was published six times, once per runtime. Opt-out closes at the end of August.

The Cloud Run functions upgrade tool went GA, for moving 1st gen functions to Cloud Run functions. If you still run 1st gen, the supported path off it is now a supported tool rather than a manual rewrite.

Cloud Run picked up NVIDIA L4 GPU driver 580.x.x for services, jobs and worker pools. Cloud Workstations gained Compute Engine suspend and resume in Preview, so a workstation can suspend at its idle timeout instead of shutting down β€” faster resume, and the state survives. GKE shipped its 2026-R33 version updates across channels, and Google Distributed Cloud released 1.35.400-gke.81 for both VMware and bare metal.

AI and agents

Gemini 3.7 Flash reached general availability in the global, us and eu regions, in both Gemini Enterprise and the Agent Platform. It is not yet in the Gemini Enterprise mobile app, which Google called out explicitly. Vertex AI Search can now generate Agent Search answers with Gemini 3.5 Flash.

Gemini Enterprise had the busiest week of any product here: custom skills you can create, upload and share; a GitHub connector with data federation at GA; spend limits and overage management for invoiced billing accounts; CSV export of user data; and the AlphaEvolve HPC solution for distributed containerised workloads. Apigee API hub added gcloud commands to configure and deploy MCP servers, and Cloud Trace now generates spans automatically for tools/call operations on several remote MCP servers β€” observability for agent tool calls arriving as a platform feature.

Networking and operations

Connectivity Tests can now use a Cloud Run job as a source endpoint, closing a real gap: testing reachability *from* serverless compute previously meant inferring it. Eventarc triggers for Cloud Run destinations can now specify a single delivery attempt with no retries, which matters for any handler that is not idempotent. Cloud Trace generates exemplars for SQL-backed custom dashboard charts, and Error Reporting now accepts Rust stack traces via std::backtrace with RUST_BACKTRACE=1.

The routine remainder

Of the week's 169 distinct changes, 89 were routine version and image notes that are listed here as a group rather than individually, because itemising them would bury everything above:

  • 65 Container-Optimized OS image notes β€” CVE fixes and package bumps across image families. Relevant if you pin COS images; otherwise they arrive on their own.
  • 12 GKE version-update notes β€” the 2026-R33 rollout across Rapid, Regular and Stable channels.
  • 12 Google SecOps Marketplace integration updates β€” version bumps to CrowdStrike Falcon, Microsoft Graph Mail, Microsoft 365 Defender, Cisco Umbrella, Active Directory and others. Several add real actions rather than fixes; Microsoft Graph Mail gained Block Domain, Block Sender and inbox-rule management.

What I would act on

  1. Check whether anything you run on App Engine still needs TLS below 1.2, this month. The opt-out closes at the end of August. This is the only item in the week where inaction has a deadline and a failure mode.
  2. Find out whether you call the Cloud Hub App Topology API. Billing changes on 15 September. A daily free allotment covers light use, but polling it on a schedule is now metered.
  3. If you have steady G2 or G4 GPU spend, re-run the commitment maths. Flexible CUDs on those families are new this week, and flexible commitments survive a change of machine shape in a way resource-based ones do not.
  4. Turn on the LLM API key detectors in Sensitive Data Protection. Three new infoTypes, available in every region, covering the credential most likely to be sitting in a log or a prompt right now. This is an afternoon's work with a disproportionate payoff.
  5. If you still run 1st gen Cloud Functions, try the upgrade tool now that it is GA. Not urgent this week, but the path is now supported and the tooling will not get better by waiting.

Comments

How was your experience?
Your feedback helps improve this site.
PoorExcellent