Copyright 2014-2026 Google Inc. All rights reserved.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
581.0.0 (2026-08-18)
Breaking Changes
- (Cloud Services) Removed
gcloud beta services mcp enable,gcloud beta services mcp disable, andgcloud beta services mcp listas MCP enablement is no longer required and they have been functioning as no-ops.
AI Platform
Added
gcloud beta ai semantic-governance-policy-engine deprovisioncommand to tear down a semantic governance policy engine, including its tenant project, GKE cluster, and PSC service attachments.Promoted
gcloud ai semantic-governance-policies(create,describe,update,delete,list) andgcloud ai semantic-governance-policy-engine(describe,update,deprovision) commands from beta to GA.
BigQuery
- Added fields
precedenceandconditionto the commandsbq ls --reservation_assignmentandbq show --reservation_assignmentoutput. - Added the new
AUTOMATIC_MATERIALIZED_VIEW_REFRESHjob type for users to create reservation assignments with.
Cloud Auth
- Enabled Enterprise Certificate Proxy (ECP) HTTP Proxy by default for context-aware mTLS requests.
Cloud Bigtable
- Rebuilt cbt cli with newer version of bigtable client for CVE-2026-39883.
Cloud IAM
- Updated
gcloud iam workforce-pools create-cred-configandgcloud iam workforce-pools create-login-configto accept short-format provider audiences (<pool>/<provider>). - Added
gcloud beta iam workforce-pools providers create-samlandgcloud beta iam workforce-pools providers update-samlcommands.
Cloud Services
- API Keys: Added
--appendflag togcloud services api-keys updatecommand to merge new application and API target restrictions with existing key restrictions instead of replacing them.
Cluster Director
- Fixed
gcloud cluster-director clusters createto not create default compute resources when they are overridden by the user. - Updated
gcloud cluster-director clusters createto default tohyperdisk-balancedboot disks and restrict persistent disks (PD) for non-N2 and non-CT5P machine types. - Fixed a validation error during cluster updates that concurrently modified storage resources and Slurm node sets.
Compute Engine
- Added
gcloud compute target-ssl-proxies test-iam-permissionscommand to test IAM permissions on a Compute Engine target SSL proxy inbeta,preview, andGA. - Added
--max-stream-durationflag togcloud compute backend-services createandupdatecommands in beta, preview, and GA. - Added
gcloud compute packet-mirrorings test-iam-permissionscommand for beta, preview and GA tracks.
Container
- Fixed issue where
gcloudCLI would crash on corrupted~/.kube/config. Now you will now get a more detailed explanation about which section and line is wrong, to make troubleshooting easier. Corrupted kubeconfig will be backed up for further troubleshooting.
Database Migration
- Added
--reserved-public-ipand--reserved-public-ip-nat-ips-countflags togcloud database-migration private-connections create. - Added
--fetch-reserved-public-ipsflag togcloud database-migration connection-profiles fetch-static-ips.
Kubernetes Engine
- Add
--enable-slice-controllerflag ingcloud container clusters createandgcloud container clusters update.
Oracle Database
- Added
--total-vm-storage-size-gbflag togcloud oracle-database cloud-exadata-infrastructures configure-exascaleand--properties-vm-backup-storage-type,--properties-vm-file-system-storage-typeflags togcloud oracle-database cloud-vm-clusters createto support Exascale VM storage options.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
580.0.0 (2026-08-11)
Breaking Changes
- (Google Cloud CLI) The
google-cloud-sdkSnap package will be deprecated and removed on September 29th, 2026. Please migrate to thegoogle-cloud-clipackage. For more information, see https://docs.cloud.google.com/sdk/docs/downloads-snap.
Google Cloud CLI
- Fixed Google Compute Engine residency detection to prevent authentication failures due to transient issues and command latency regressions in non-Google Cloud environments.
Apihub
- Promoted
gcloud apihub locations configure-and-deploy-servercommand to GA. This command configures and deploys an MCP (Model Context Protocol) server on Apigee X via API Hub.
Certificate Authority Service
- Added first-party activation support to
gcloud privateca subordinates activatevia--issuer-pool,--issuer-location, and--issuer-caflags. - Added suggestion to use
gcloud privateca subordinates activatewhengcloud privateca subordinates createwith issuer flags fails due to an already existing subordinate CA.
Certificate Manager
- Added
--tagsflag togcloud certificate-managercreate commands (certificates create,dns-authorizations create,issuance-configs create,maps create, andtrust-configs create).
Cloud Backup DR
- Added selective disk backup properties (
boot-disk-onlyanddisk-exclusion-labels) under--compute-instance-propertiesingcloud backup-dr backup-plans createandupdatecommands. - Added
--source-instance-boot-diskand--source-instance-disk-device-nameflags togcloud backup-dr backups restore diskfor individual disk restore from compute instance backup.
Cloud Composer
- Enabled the 'backfill' Airflow CLI sub-command for Composer environments running Airflow 3.
- Enabled the 'config lint' Airflow CLI sub-command for Composer environments running Airflow 2.11.0 or higher.
Cloud Dataflow
- Added
gcloud dataflow jobs pauseandgcloud dataflow jobs resumecommands. - Added
--enable-turnkey-alertsflag togcloud dataflow jobs runandgcloud dataflow flex-template run.
Cloud IAM
- Added support for X.509 certificate-based credentials and locational mTLS endpoints to
gcloud iam workload-identity-pools create-cred-config.
Cloud Spanner
- Update
gcloud spanner backups listcommand to display INSTANCE_PARTITIONS column in GA track.
Cloud Storage
gcloud storage rsync:- Skipping syncing files which goes outside of destination directory.
Cluster Director
- Updated
gcloud cluster-director clusters createto default to dynamic nodes when using flex start.
Compute Engine
- Added
gcloud compute resource-policies test-iam-permissionscommand to test IAM permissions on a Compute Engine resource policy in GA, beta, preview, and alpha. - Added
gcloud compute snapshot-groups set-iam-policycommand in beta. - Added
--kms-key-service-accounttogcloud compute disks create,gcloud compute images create,gcloud compute machine-images createandgcloud compute snapshots createfor beta track. - Added
--boot-disk-kms-key-service-accountand--instance-kms-key-service-accounttogcloud compute instances createandgcloud compute instance-templates createfor beta track. - Added
--consistent-hash-minimum-ring-sizeflag togcloud compute backend-services createandupdatecommands. - Added
--circuit-breakers-max-requestsflag togcloud compute backend-services createandupdatecommands. - Added
gcloud compute backend-services test-iam-permissionscommand to test IAM permissions on a Compute Engine backend service in beta, preview, and GA. - Added
gcloud compute ssl-policies test-iam-permissionscommand to test IAM permissions on a Compute Engine SSL policy in beta. - Added
gcloud compute firewall-policies test-iam-permissionscommand. - Promoted
--graceful-shutdown,--graceful-shutdown-max-duration, and--no-graceful-shutdownflags to the GA track forgcloud compute instancesandgcloud compute instance-templatescommands. - Added
--identity-typeflag togcloud compute instances create,gcloud compute instances update, andgcloud compute instance-templates createin alpha. - Promoted exapool capacity flags to beta and GA tracks for
gcloud compute storage-pools updatecommand. - Added
--maintenance-freeze-durationand--clear-maintenance-freeze-durationflags togcloud compute instances set-schedulingandgcloud compute instances createin beta. - Added
gcloud compute images test-iam-permissionscommand to test IAM permissions on a Compute Engine image in beta, preview, and GA.
Device Run
- Promoted
gcloud device-run sessions waitcommand to beta. - Updated
--instrumentation-timeoutflag ofgcloud beta device-run sessions submit instrumentationto allow a maximum duration of 3 hours. - Updated
gcloud device-run devices describeto displayhardware_typeinstead ofform. - Updated
gcloud device-run devices listto displayHARDWARE_TYPEcolumn instead ofFORM.
GKE Hub
- Promoted API field schema for
--fleet-default-member-configflag ongcloud container fleet|hub config-management enablecommand tobeta.
Metastore
- Updated
gcloud beta metastore services migrations startto support migrations to Lakehouse runtime catalog(s). - Deprecated Cloud SQL migration arguments in
gcloud beta metastore services migrations start.
Network Connectivity
- Added
--export-psc-published-services-and-regional-google-apisand--export-psc-global-google-apisflags togcloud beta network-connectivity hubs createandgcloud beta network-connectivity hubs updatecommands.
Network Security
- Promoted
mcpandpolicyProfilefields to GA ingcloud network-security authz-policies importandexportcommands. - Made
loadBalancingSchemeoptional ingcloud network-security authz-policies importandexportcommands.
Network Services
- Promoted
gcloud network-services telemetry-policies deletecommand to BETA.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
579.0.0 (2026-08-04)
Breaking Changes
- (API Registry) Removed
gcloud api-registry mcp enableandgcloud api-registry mcp disable. MCP server enablement is no longer required; enabling the underlying service is sufficient. - (Compute Engine) Removed
PRESERVED_STATEcolumn fromgcloud compute instance-groups managed list-instancesoutput in beta.
AI
- Route
gcloud airequests for theusmulti-region to the Vertex AI multi-regional (REP) endpoint.
Agent Identity
- Added
--three-legged-oauth-default-continue-uriflag togcloud agent-identity auth-providers createandupdatecommands.
Cloud Auth
- Enabled ECP HTTP Proxy support for external users (disabled by default).
- Added optional
--ecp-http-proxyflag togcloud auth enterprise-certificate-config createto support custom ECP HTTP proxy binary paths.
Cloud Dataproc
- Promoted
--master-instance-selection,--master-instance-flexibility-policy-file,--worker-instance-selection,--worker-instance-flexibility-policy-file,--secondary-worker-instance-selection, and--secondary-worker-instance-flexibility-policy-fileflags to GA forgcloud dataproc clusters createandgcloud dataproc workflow-templates set-managed-cluster.
Cloud Firestore Emulator
- Added support for
--require-indexesand--index-fileflags ingcloud emulators firestore startcommand.
Cloud Functions
- Added
all-trafficas an allowed value for--direct-vpc-egressflag ingcloud functions deploy. - Promoted
gcloud functions upgradecommand to GA.
Cloud NetApp
- Added
gcloud netapp volumes start-splitandgcloud netapp volumes get-split-statuscommands to GA track.
Cloud Quotas
- Promoted
gcloud quotassurface (info, preferences, and adjuster settings) to General Availability (GA).
Cloud SQL
- Modified
gcloud sql instances reencryptto support zero-downtime re-encryption for most Cloud SQL instances, removing the previous downtime warning. Instances using C4, C4A, or N4 machine types are not yet supported for zero-downtime re-encryption; they will still restart during this operation and prompt a downtime warning.
Cloud Services
- Updated
gcloud beta services mcp enablecommand to be a no-op, as MCP enablement is no longer required.
Cluster Director
- Fixed an issue where the default zone for cluster resources (storage, network, etc.) was always set to the location's "b" zone, overriding the user-specified zone in compute flags.
- Renamed
--blueprintflag to--reference-architectureingcloud beta cluster-director clusters create.
Compute Engine
- Promoted
gcloud compute hostsandgcloud compute reservations hoststo GA. - Updated
gcloud compute reservations hosts listandgcloud compute reservations hosts describeto require--reservationwhen--reservation-blockis specified. - Added support for 3500GB, and 7000GB partition sizes when creating
local SSDs via
gcloud compute instances createandgcloud compute instance-templates create. - Promoted
--igmp-queryflag in--network-interfaceofgcloud compute instance-templates createto GA. - Promoted
--igmp-queryflag ingcloud compute instances network-interfaces addto GA. - Promoted
--igmp-queryflag in--network-interfaceofgcloud compute instances bulk createto GA.* Addedgcloud compute http-health-checks test-iam-permissionscommand. - Added
--routing-modeflag togcloud compute service-attachments createandupdatecommands in beta. - Added
gcloud compute snapshot-groups test-iam-permissionscommand in beta release track. - Added
gcloud compute instances test-iam-permissionscommand to test IAM permissions on a Compute Engine virtual machine instance in GA, beta, and preview. - Added
gcloud compute interconnects groups set-iam-policycommand to set IAM policy on an interconnect group in beta, preview, and GA. - Added
--exapool-capacity-optimized-capacity,--exapool-read-optimized-capacity, and--exapool-write-optimized-capacityflags togcloud alpha compute storage-pools updatefor Exapool storage pools. - Added Arm
CCAsupport to theconfidential-compute-typeoption ingcloud compute instance create. - Added
gcloud compute network-firewall-policies test-iam-permissionscommand. - Added
gcloud compute disks test-iam-permissionscommand to test IAM permissions on a Compute Engine disk. - Promoted
--ipv6-network-tierflag ofgcloud compute networks subnets createandgcloud compute networks subnets updateto beta. - Added
STANDARDoption to--ipv6-network-tierflag ofgcloud compute instances create,gcloud compute instance-templates create,gcloud compute instances network-interfaces add, andgcloud compute instances network-interfaces updatein beta. - Added
gcloud compute routers test-iam-permissionscommand to test specific IAM permissions on a Compute Engine router in beta.
Compute Firewall Policies
- Promoted new ULL_POLICY value for
--policy-typeflag ofgcloud compute network-firewall-policies createto GA.
Distributed Cloud Edge
- Promoted
gcloud edge-cloud zones listto GA.
GKE Hub
- Promoted
gcloud container fleet|hub config-management updatecommand tobeta.
Identity and Access Management
- Added
gcloud iam access-policies create|delete|describe|list|update|search-policy-bindingscommands to allow management of access policy resources. - Added
--target-resourceflag togcloud iam policy-bindings create.
Kpt
- Updated kpt to v1.0.0-beta.67. See https://github.com/kptdev/kpt/releases/tag/v1.0.0-beta.67 for more details.
Kubernetes Engine
- Updated default kubectl to 1.35.6.
- Additional kubectl versions:
- 1.30.14
- 1.31.14
- 1.32.13
- 1.33.13