Copyright 2014-2026 Google Inc. All rights reserved.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
581.0.0 (2026-08-18)
Breaking Changes
- (Cloud Services) Removed
gcloud beta services mcp enable,gcloud beta services mcp disable, andgcloud beta services mcp listas MCP enablement is no longer required and they have been functioning as no-ops.
AI Platform
Added
gcloud beta ai semantic-governance-policy-engine deprovisioncommand to tear down a semantic governance policy engine, including its tenant project, GKE cluster, and PSC service attachments.Promoted
gcloud ai semantic-governance-policies(create,describe,update,delete,list) andgcloud ai semantic-governance-policy-engine(describe,update,deprovision) commands from beta to GA.
BigQuery
- Added fields
precedenceandconditionto the commandsbq ls --reservation_assignmentandbq show --reservation_assignmentoutput. - Added the new
AUTOMATIC_MATERIALIZED_VIEW_REFRESHjob type for users to create reservation assignments with.
Cloud Auth
- Enabled Enterprise Certificate Proxy (ECP) HTTP Proxy by default for context-aware mTLS requests.
Cloud Bigtable
- Rebuilt cbt cli with newer version of bigtable client for CVE-2026-39883.
Cloud IAM
- Updated
gcloud iam workforce-pools create-cred-configandgcloud iam workforce-pools create-login-configto accept short-format provider audiences (<pool>/<provider>). - Added
gcloud beta iam workforce-pools providers create-samlandgcloud beta iam workforce-pools providers update-samlcommands.
Cloud Services
- API Keys: Added
--appendflag togcloud services api-keys updatecommand to merge new application and API target restrictions with existing key restrictions instead of replacing them.
Cluster Director
- Fixed
gcloud cluster-director clusters createto not create default compute resources when they are overridden by the user. - Updated
gcloud cluster-director clusters createto default tohyperdisk-balancedboot disks and restrict persistent disks (PD) for non-N2 and non-CT5P machine types. - Fixed a validation error during cluster updates that concurrently modified storage resources and Slurm node sets.
Compute Engine
- Added
gcloud compute target-ssl-proxies test-iam-permissionscommand to test IAM permissions on a Compute Engine target SSL proxy inbeta,preview, andGA. - Added
--max-stream-durationflag togcloud compute backend-services createandupdatecommands in beta, preview, and GA. - Added
gcloud compute packet-mirrorings test-iam-permissionscommand for beta, preview and GA tracks.
Container
- Fixed issue where
gcloudCLI would crash on corrupted~/.kube/config. Now you will now get a more detailed explanation about which section and line is wrong, to make troubleshooting easier. Corrupted kubeconfig will be backed up for further troubleshooting.
Database Migration
- Added
--reserved-public-ipand--reserved-public-ip-nat-ips-countflags togcloud database-migration private-connections create. - Added
--fetch-reserved-public-ipsflag togcloud database-migration connection-profiles fetch-static-ips.
Kubernetes Engine
- Add
--enable-slice-controllerflag ingcloud container clusters createandgcloud container clusters update.
Oracle Database
- Added
--total-vm-storage-size-gbflag togcloud oracle-database cloud-exadata-infrastructures configure-exascaleand--properties-vm-backup-storage-type,--properties-vm-file-system-storage-typeflags togcloud oracle-database cloud-vm-clusters createto support Exascale VM storage options.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
580.0.0 (2026-08-11)
Breaking Changes
- (Google Cloud CLI) The
google-cloud-sdkSnap package will be deprecated and removed on September 29th, 2026. Please migrate to thegoogle-cloud-clipackage. For more information, see https://docs.cloud.google.com/sdk/docs/downloads-snap.
Google Cloud CLI
- Fixed Google Compute Engine residency detection to prevent authentication failures due to transient issues and command latency regressions in non-Google Cloud environments.
Apihub
- Promoted
gcloud apihub locations configure-and-deploy-servercommand to GA. This command configures and deploys an MCP (Model Context Protocol) server on Apigee X via API Hub.
Certificate Authority Service
- Added first-party activation support to
gcloud privateca subordinates activatevia--issuer-pool,--issuer-location, and--issuer-caflags. - Added suggestion to use
gcloud privateca subordinates activatewhengcloud privateca subordinates createwith issuer flags fails due to an already existing subordinate CA.
Certificate Manager
- Added
--tagsflag togcloud certificate-managercreate commands (certificates create,dns-authorizations create,issuance-configs create,maps create, andtrust-configs create).
Cloud Backup DR
- Added selective disk backup properties (
boot-disk-onlyanddisk-exclusion-labels) under--compute-instance-propertiesingcloud backup-dr backup-plans createandupdatecommands. - Added
--source-instance-boot-diskand--source-instance-disk-device-nameflags togcloud backup-dr backups restore diskfor individual disk restore from compute instance backup.
Cloud Composer
- Enabled the 'backfill' Airflow CLI sub-command for Composer environments running Airflow 3.
- Enabled the 'config lint' Airflow CLI sub-command for Composer environments running Airflow 2.11.0 or higher.
Cloud Dataflow
- Added
gcloud dataflow jobs pauseandgcloud dataflow jobs resumecommands. - Added
--enable-turnkey-alertsflag togcloud dataflow jobs runandgcloud dataflow flex-template run.
Cloud IAM
- Added support for X.509 certificate-based credentials and locational mTLS endpoints to
gcloud iam workload-identity-pools create-cred-config.
Cloud Spanner
- Update
gcloud spanner backups listcommand to display INSTANCE_PARTITIONS column in GA track.
Cloud Storage
gcloud storage rsync:- Skipping syncing files which goes outside of destination directory.
Cluster Director
- Updated
gcloud cluster-director clusters createto default to dynamic nodes when using flex start.
Compute Engine
- Added
gcloud compute resource-policies test-iam-permissionscommand to test IAM permissions on a Compute Engine resource policy in GA, beta, preview, and alpha. - Added
gcloud compute snapshot-groups set-iam-policycommand in beta. - Added
--kms-key-service-accounttogcloud compute disks create,gcloud compute images create,gcloud compute machine-images createandgcloud compute snapshots createfor beta track. - Added
--boot-disk-kms-key-service-accountand--instance-kms-key-service-accounttogcloud compute instances createandgcloud compute instance-templates createfor beta track. - Added
--consistent-hash-minimum-ring-sizeflag togcloud compute backend-services createandupdatecommands. - Added
--circuit-breakers-max-requestsflag togcloud compute backend-services createandupdatecommands. - Added
gcloud compute backend-services test-iam-permissionscommand to test IAM permissions on a Compute Engine backend service in beta, preview, and GA. - Added
gcloud compute ssl-policies test-iam-permissionscommand to test IAM permissions on a Compute Engine SSL policy in beta. - Added
gcloud compute firewall-policies test-iam-permissionscommand. - Promoted
--graceful-shutdown,--graceful-shutdown-max-duration, and--no-graceful-shutdownflags to the GA track forgcloud compute instancesandgcloud compute instance-templatescommands. - Added
--identity-typeflag togcloud compute instances create,gcloud compute instances update, andgcloud compute instance-templates createin alpha. - Promoted exapool capacity flags to beta and GA tracks for
gcloud compute storage-pools updatecommand. - Added
--maintenance-freeze-durationand--clear-maintenance-freeze-durationflags togcloud compute instances set-schedulingandgcloud compute instances createin beta. - Added
gcloud compute images test-iam-permissionscommand to test IAM permissions on a Compute Engine image in beta, preview, and GA.
Device Run
- Promoted
gcloud device-run sessions waitcommand to beta. - Updated
--instrumentation-timeoutflag ofgcloud beta device-run sessions submit instrumentationto allow a maximum duration of 3 hours. - Updated
gcloud device-run devices describeto displayhardware_typeinstead ofform. - Updated
gcloud device-run devices listto displayHARDWARE_TYPEcolumn instead ofFORM.
GKE Hub
- Promoted API field schema for
--fleet-default-member-configflag ongcloud container fleet|hub config-management enablecommand tobeta.
Metastore
- Updated
gcloud beta metastore services migrations startto support migrations to Lakehouse runtime catalog(s). - Deprecated Cloud SQL migration arguments in
gcloud beta metastore services migrations start.
Network Connectivity
- Added
--export-psc-published-services-and-regional-google-apisand--export-psc-global-google-apisflags togcloud beta network-connectivity hubs createandgcloud beta network-connectivity hubs updatecommands.
Network Security
- Promoted
mcpandpolicyProfilefields to GA ingcloud network-security authz-policies importandexportcommands. - Made
loadBalancingSchemeoptional ingcloud network-security authz-policies importandexportcommands.
Network Services
- Promoted
gcloud network-services telemetry-policies deletecommand to BETA.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
579.0.0 (2026-08-04)
Breaking Changes
- (API Registry) Removed
gcloud api-registry mcp enableandgcloud api-registry mcp disable. MCP server enablement is no longer required; enabling the underlying service is sufficient. - (Compute Engine) Removed
PRESERVED_STATEcolumn fromgcloud compute instance-groups managed list-instancesoutput in beta.
AI
- Route
gcloud airequests for theusmulti-region to the Vertex AI multi-regional (REP) endpoint.
Agent Identity
- Added
--three-legged-oauth-default-continue-uriflag togcloud agent-identity auth-providers createandupdatecommands.
Cloud Auth
- Enabled ECP HTTP Proxy support for external users (disabled by default).
- Added optional
--ecp-http-proxyflag togcloud auth enterprise-certificate-config createto support custom ECP HTTP proxy binary paths.
Cloud Dataproc
- Promoted
--master-instance-selection,--master-instance-flexibility-policy-file,--worker-instance-selection,--worker-instance-flexibility-policy-file,--secondary-worker-instance-selection, and--secondary-worker-instance-flexibility-policy-fileflags to GA forgcloud dataproc clusters createandgcloud dataproc workflow-templates set-managed-cluster.
Cloud Firestore Emulator
- Added support for
--require-indexesand--index-fileflags ingcloud emulators firestore startcommand.
Cloud Functions
- Added
all-trafficas an allowed value for--direct-vpc-egressflag ingcloud functions deploy. - Promoted
gcloud functions upgradecommand to GA.
Cloud NetApp
- Added
gcloud netapp volumes start-splitandgcloud netapp volumes get-split-statuscommands to GA track.
Cloud Quotas
- Promoted
gcloud quotassurface (info, preferences, and adjuster settings) to General Availability (GA).
Cloud SQL
- Modified
gcloud sql instances reencryptto support zero-downtime re-encryption for most Cloud SQL instances, removing the previous downtime warning. Instances using C4, C4A, or N4 machine types are not yet supported for zero-downtime re-encryption; they will still restart during this operation and prompt a downtime warning.
Cloud Services
- Updated
gcloud beta services mcp enablecommand to be a no-op, as MCP enablement is no longer required.
Cluster Director
- Fixed an issue where the default zone for cluster resources (storage, network, etc.) was always set to the location's "b" zone, overriding the user-specified zone in compute flags.
- Renamed
--blueprintflag to--reference-architectureingcloud beta cluster-director clusters create.
Compute Engine
- Promoted
gcloud compute hostsandgcloud compute reservations hoststo GA. - Updated
gcloud compute reservations hosts listandgcloud compute reservations hosts describeto require--reservationwhen--reservation-blockis specified. - Added support for 3500GB, and 7000GB partition sizes when creating
local SSDs via
gcloud compute instances createandgcloud compute instance-templates create. - Promoted
--igmp-queryflag in--network-interfaceofgcloud compute instance-templates createto GA. - Promoted
--igmp-queryflag ingcloud compute instances network-interfaces addto GA. - Promoted
--igmp-queryflag in--network-interfaceofgcloud compute instances bulk createto GA.* Addedgcloud compute http-health-checks test-iam-permissionscommand. - Added
--routing-modeflag togcloud compute service-attachments createandupdatecommands in beta. - Added
gcloud compute snapshot-groups test-iam-permissionscommand in beta release track. - Added
gcloud compute instances test-iam-permissionscommand to test IAM permissions on a Compute Engine virtual machine instance in GA, beta, and preview. - Added
gcloud compute interconnects groups set-iam-policycommand to set IAM policy on an interconnect group in beta, preview, and GA. - Added
--exapool-capacity-optimized-capacity,--exapool-read-optimized-capacity, and--exapool-write-optimized-capacityflags togcloud alpha compute storage-pools updatefor Exapool storage pools. - Added Arm
CCAsupport to theconfidential-compute-typeoption ingcloud compute instance create. - Added
gcloud compute network-firewall-policies test-iam-permissionscommand. - Added
gcloud compute disks test-iam-permissionscommand to test IAM permissions on a Compute Engine disk. - Promoted
--ipv6-network-tierflag ofgcloud compute networks subnets createandgcloud compute networks subnets updateto beta. - Added
STANDARDoption to--ipv6-network-tierflag ofgcloud compute instances create,gcloud compute instance-templates create,gcloud compute instances network-interfaces add, andgcloud compute instances network-interfaces updatein beta. - Added
gcloud compute routers test-iam-permissionscommand to test specific IAM permissions on a Compute Engine router in beta.
Compute Firewall Policies
- Promoted new ULL_POLICY value for
--policy-typeflag ofgcloud compute network-firewall-policies createto GA.
Distributed Cloud Edge
- Promoted
gcloud edge-cloud zones listto GA.
GKE Hub
- Promoted
gcloud container fleet|hub config-management updatecommand tobeta.
Identity and Access Management
- Added
gcloud iam access-policies create|delete|describe|list|update|search-policy-bindingscommands to allow management of access policy resources. - Added
--target-resourceflag togcloud iam policy-bindings create.
Kpt
- Updated kpt to v1.0.0-beta.67. See https://github.com/kptdev/kpt/releases/tag/v1.0.0-beta.67 for more details.
Kubernetes Engine
- Updated default kubectl to 1.35.6.
- Additional kubectl versions:
- 1.30.14
- 1.31.14
- 1.32.13
- 1.33.13
- 1.34.10
- 1.35.7
- 1.36.3
Network Services
- Deprecated
clientTlsPolicyfield ingcloud network-services endpoint-policies. - Updated
gcloud network-services endpoint-policiesresource name pattern to support regional locations.
Vmware Engine
- Added
--kms-keyflag togcloud vmware private-clouds create. Specifying this flag with a valid KMS key resource name enables CMEK. - Added
--encryption-typeand--kms-keyflags togcloud vmware private-clouds update.--kms-key(valid KMS key resource name) is required when--encryption-typeis CMEK.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
578.0.0 (2026-07-28)
Breaking Changes
- (Database Migration) Made
--auto-commitflag the default forgcloud database-migration conversion-workspaces seed|convert|import-rulesoperations. To disable auto-committing, use--no-auto-commitflag. The
run_bq_commandtool exposes the BigQuery CLI (bq) within the Cloud CLI remote MCP server. You can send natural language prompts to your AI application to execute specific BigQuery SQL commands on your behalf.For more information, see Use the Cloud CLI remote MCP server.
Google Cloud CLI
- Fixed an issue where running
gcloud initcrashed when Enterprise Certificate Proxy (ECP) binaries were missing from configuration. - Updated macOS Python Virtualenv for the
gcloudCLI to 3.14.6.
AlloyDB
- Promote AlloyDB Backup DR restore flags (
--backupdr-backupand--backupdr-data-source) to the GA track.
BigLake
- Fixed a bug where
gcloud biglake iceberg tablescommands failed to send theX-Iceberg-Access-Delegation: vended-credentialsheader.
BigQuery
- Added
-f/--forcesupport tobq rm --connectionto ignore NOT_FOUND errors if the connection does not exist. - Fixed reading configuration from
gcloudCLI with--nouse_google_authflag. - Added a predefined label for jobs created in specific metrics environments.
- Updated the help text for several global flags.
- Updated command format in the user-agent HTTP header of API requests.
Cloud Backup DR
- Added
--log-retention-daysflag acrossgcloud backup-dr backup-plans createandupdateacross all release tracks to enable Point-in-Time Recovery (PITR) log retention configuration.
Cloud Bigtable
- Added
--ignore-warningsflag togcloud bigtable instances tables updateandgcloud bigtable tables update. - Promoted
--ignore-warningsflag ofgcloud bigtable materialized-views createto GA.
Cloud Composer
- Enabled Airflow CLI commands for Composer environments running Airflow 3.2.
Cloud IAM
- Promoted
enabled-for-users-groupsoption for--scim-usageflag to beta ingcloud beta iam workforce-pools providers.
Cloud Run
- Added
--sandbox-launcherflag togcloud beta run jobsandgcloud beta run worker-poolscommand groups to allow setting a container as sandbox launcher when creating or updating a Cloud Run job or a worker pool.
Cloud Workstations
- Added
--idle-actionflag togcloud alpha workstations configs create,gcloud alpha workstations configs update,gcloud beta workstations configs create, andgcloud beta workstations configs updatecommands.
Compute Engine
- Added
--network-tierflag togcloud compute public-advertised-prefixes createin beta. - Added
--metadata-filterflag togcloud compute forwarding-rules createcommand across all release tracks. - Added
--metadata-filterflag togcloud compute forwarding-rules updatecommands across all release tracks. - Added
gcloud compute machine-images test-iam-permissionscommand to test IAM permissions on a Compute Engine machine image in beta, preview, and GA. - Promoted
regex_rewritesupport inurl_rewriteblock to beta forgcloud compute url-maps. - Promoted the following
gcloud compute routerscommand groups to GA:add-named-set,add-named-set-element,download-named-set,get-named-set,list-named-sets,remove-named-set,remove-named-set-element, andupload-named-set. - Added
gcloud compute health-sources test-iam-permissionscommand to test IAM permissions on a health source. - Added
gcloud compute instant-snapshot-groups set-iam-policycommand to set the IAM policy for a Compute Engine instant snapshot group. - Added
gcloud compute networks subnets test-iam-permissionscommand in beta, preview, and GA. - Added
gcloud compute image-views describecommand in beta. - Added
gcloud compute snapshots test-iam-permissionsto test IAM permissions for Compute Engine snapshots. - Added
gcloud compute interconnects attachments groups set-iam-policycommand to set IAM policy on an interconnect attachment group in beta, preview, and GA. - Added
--internal-rangeflag togcloud compute addresses createto support allocating global internal IP addresses from an Internal Range for Private Service Connect. - Updated
gcloud compute reservations hosts listandgcloud compute reservations hosts describeto require--reservationwhen--reservation-blockis specified.
Developer Connect
- Updated
gcloud beta developer-connect account-connectorscommands to support Bring Your Own (BYO) and Bitbucket Cloud (BBC) connection types.
GKE Hub
- Promoted
--view,--memberships,--filter, and--sort-byflags ongcloud container fleet|hub config-management describecommand tobeta.
Network Management
- Added
--source-dms-private-connectionflag togcloud network-management connectivity-tests.
Secret Manager
- Added the
--secret-typeflag togcloud secrets createto support creating secrets of different types (e.g. Cloud SQL credentials). - Added the
gcloud secrets enable-managed-rotationcommand to enable managed rotation for a secret using Cloud SQL credentials. - Added the
gcloud secrets rotate-secretcommand to rotate a secret.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
577.0.0 (2026-07-21)
Agent Identity
- Promoted
gcloud agent-identity auth-providersandgcloud agent-identity access-summariesto GA.
AlloyDB
- Modify flag
--no-enable-autoscalerofgcloud beta alloydb instances create|updatecommands to only set theenabledfield tofalseand not clear autoscaling config. - Modify
gcloud beta alloydb instances updatecommand to only allow one of--autoscaler-delete-schedule,--autoscaler-disable-schedule,--autoscaler-enable-schedule, or--autoscaler-set-scheduleto be specified.
Artifact Registry
- Added
connector-repositorymode togcloud artifacts repositories create.
BigQuery
- Added support for
--s3_service_directory_serviceflag to pass custom Service Directory endpoints for AWS connection make and update operations. This is used for routing traffic over a private network connection through Cross-Cloud Interconnect. - Updated the data source of agent name value set in the user agent HTTP header.
- Stopped enforcing
bq initwhen--oauth_access_tokenis provided.
Cloud Bigtable
- fix: cbt cli escape row keys and column qualifiers in printRow.
Cloud Firestore Emulator
- Release Cloud Firestore emulator v1.22.0
- Added DML support for the Firestore Pipelines API
- Added ability to model when composite indexes are required in Datastore mode using new
--require-indexesand--index-fileflags - Added depreciation warning for JRE versions <25
Cloud Key Management Service
- (GA) Added
--folderflag togcloud kms autokey-config show-effective-configto retrieve the effective Cloud KMS Autokey configuration for folders. The--projectand--folderflags are now optional, defaulting to the current project.
Cloud Workstations
- Added
gcloud beta workstations suspendandgcloud alpha workstations suspendcommands.
Compute Engine
- Added
gcloud compute machine-images test-iam-permissionscommand to test IAM permissions on a Compute Engine machine image in beta, preview, and GA. - Promoted
regex_rewritesupport inurl_rewriteblock to beta forgcloud compute url-maps. - Promoted the following
gcloud compute routerscommand groups to GA:add-named-set,add-named-set-element,download-named-set,get-named-set,list-named-sets,remove-named-set,remove-named-set-element, andupload-named-set. - Added
gcloud compute health-sources test-iam-permissionscommand to test IAM permissions on a health source. - Added
--logging-http-request-headersand--logging-http-response-headersflags togcloud compute backend-services createandupdatecommands to configure Cloud Logging HTTP headers for external L7 load balancers. - Added
--local-ssd-encryption-modeflag togcloud compute instances createto specify the encryption mode for Local SSDs. - Deprecated customer-supplied encryption keys (CSEK) flags
--csek-key-file,--require-csek-key-create,--source-machine-image-csek-key-file,--source-disk-csek-key,--source-disk-key-file, and--source-instant-snapshot-key-fileforgcloud computecommands.
GKE Hub
- Changed both
--configflag ongcloud beta container fleet|hub config-management applycommand and--fleet-default-member-configflag ongcloud beta container fleet|hub config-management enablecommand to no longer defaultspec.upgrades: manualpopulation since auto-upgrades is no longer supported from Config Sync version 1.21.0 andspec.upgrades: manualis behaviorally equivalent to not setting this field.
Kubernetes Engine
- Fix overwriting autoscaling settings in
gcloud container clusters update.
Network Security
- Updated
gcloud beta network-security authz-policies importto supportnetworkRulesandsnisfields.
Recaptcha
- Added
--universaloption togcloud recaptcha keys createandgcloud recaptcha keys update.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
576.0.0 (2026-07-14)
Breaking Changes
- (Cloud Storage) Updated
gcloud storage rsyncto default decompresses downloaded gzip files to match the behavior ofgcloud storage cp. To retain the previous behavior, use the new--do-not-decompressflag.
Google Cloud CLI
- Updated Linux bundled Python for the
gcloudCLI to 3.14.6 to resolve CVE-2026-34182. The Cloud CLI remote MCP server provides a secure environment that lets you send natural language prompts to your AI application to execute command-line interface (CLI) commands on your behalf. Only
gcloudcommands are supported.For more information, see Use the Cloud CLI remote MCP server.
Artifact Registry
- Fixed a performance regression in
gcloud artifacts docker images listwhen listing a large number of image versions.
BigLake
- Promoted
gcloud biglake delta-sharing <catalogs|shares|schemas|tables>to GA. - Promoted
gcloud biglake data-product-sharing publishto GA. - Added
lakehouseoption to--catalog=typeflag togcloud biglake iceberg catalogs. - Added
gcloud biglake hive tables updateto beta.
BigQuery
- Added environment information to the user-agent HTTP header.
- Added support for
--labelflag inbq cp,bq extract, andbq loadcommands to configure job-level labels. - Fixed 'bq show' command failures displaying timestamps without fractional seconds.
Cloud Data Lineage
- Added
gcloud datalineage runscommand group to manage data lineage runs. - Added
gcloud datalineage lineage-eventscommand group to manage data lineage runs.
Cloud Dataplex
- Added
--enable-catalog-publishingflag togcloud dataplex datascans create data-documentationandgcloud dataplex datascans update data-documentationcommands. - Added
--modeflag togcloud dataplex datascans create data-profileandgcloud dataplex datascans update data-profilecommands to support specifying profiling mode.
Cloud Dataproc
- Promoted
gcloud dataproc batches submit pyspark-notebookto GA.
Cloud Identity-Aware Proxy
- Promoted support for
agent-registryresource type ingcloud iap webIAM commands to GA.
Cloud Key Management Service
- (Alpha, Beta) Added
--folderflag togcloud kms autokey-config show-effective-configto retrieve the effective Cloud KMS Autokey configuration for folders. The--projectand--folderflags are now optional, defaulting to the current project. - Added
--hsm-trusted-wrappingflag togcloud kms keys createandgcloud kms keys versions importto enable trusted wrapping capabilities. - Promoted
gcloud kms keys versions export-trusted-key-wrappedandgcloud kms keys versions import-trusted-key-wrappedto GA. - Added
--crypto-key-version-nameand--two-factor-public-key-pemflags togcloud kms single-tenant-hsm proposal createfor--operation-type=upgrade_key_trust.
Cloud Managed Kafka
- Added util function to validate and remove byte units from broker disk input.
Cloud Run
- Modified
gcloud run services proxyto fail immediately if the service has its default URL disabled.
Cloud SQL
- Upgraded
--storage-auto-increase-limitflag forgcloud sql instances createandgcloud sql instances patchcommands to GA.
Cloud Storage
- Updated
gcloud storageParallel Composite Uploads to atomically clean up temporary parts, avoiding bucket soft-delete costs.
Cluster Director
- Added support for Lustre dynamic tier in
gcloud cluster-director clusterscommands.
Compliance Manager
- Updated
gcloud compliance-managercommands to support project-level resources.
Compute Engine
- Promoted
--nat-ips-per-endpointflag to GA ingcloud compute service-attachments createandgcloud compute service-attachments update. - Promoted
gcloud compute hostsandgcloud compute reservations hoststo beta. - Added
gcloud compute sole-tenancy node-templates test-iam-permissionscommand to test IAM permissions on a node template in beta, preview, and GA. - Added
gcloud compute instant-snapshots set-iam-policycommand to support setting IAM policy bindings for instant snapshots in alpha, beta, preview, and GA. - Added
gcloud compute network-attachments test-iam-permissionscommand to test IAM permissions on a network attachment in beta, preview, and GA. - Added
gcloud beta compute instance-groups managed adopt-instancesto support adopting instances into regional managed instance groups. - Added
gcloud compute instant-snapshots test-iam-permissionscommand to test IAM permissions on an instant snapshot in beta, preview, and GA. - Added
get-iam-policyandset-iam-policycommands togcloud compute firewall-policiesandgcloud compute network-firewall-policiesto manage policy-level IAM policy. - Promote the
--locationflag ofgcloud compute interconnects updateto GA. - Added
gcloud compute backend-buckets test-iam-permissionscommand to test IAM permissions on backend buckets. - Promoted
--on-repair-allow-changing-zoneflag to GA ingcloud compute instance-groups managed createandgcloud compute instance-groups managed update. - Added
gcloud compute interconnects test-iam-permissionscommand to test IAM permissions on a Compute Engine interconnect in beta. - Added
gcloud compute instant-snapshot-groups test-iam-permissionscommand. - Added
test-iam-permissionscommand togcloud compute target-tcp-proxiesto test IAM permissions on a target TCP proxy. Global proxies are supported in all tracks, and regional proxies are supported in alpha and beta tracks. - Added support for displaying dynamic field
GRACEFUL_SHUTDOWN_TIMESTAMPtogcloud compute instance-groups managed list-instancesin GA, beta and alpha. - Added
gcloud compute service-attachments set-iam-policycommand to set IAM policy on a service attachment in beta, preview, and GA. - Added
--asyncflag togcloud compute instance-groups managed delete. - Promoted
--load-balancing-schemeflag to GA ingcloud compute target-tcp-proxies create. - Promoted
--instancesflag ofgcloud create instance-groups managed resize-requests createto GA to support specific instance names. - Added
gcloud compute reservations sub-blocks test-iam-permissionscommand to beta, preview and GA release tracks. - Added
on-update-actionenum class to--create-diskflag for an instance creation. And it is added to the following release tracks alpha, beta, preview, and GA. - Added
gcloud compute external-vpn-gateways test-iam-permissionscommand to test IAM permissions on an external VPN gateway. - Added
gcloud compute sole-tenancy node-groups test-iam-permissionscommand to test IAM permissions on a node group in alpha, beta, GA, and preview. - Promoted
--identity,--identity-certificateand--most-disruptive-allowed-actionflags to GA. - Added
gcloud compute disks bulk set-labelscommand to alpha, beta, ga, and preview release tracks.
Developer Connect
- Promoted
gcloud developer-connect insights-configs deployment-events listanddescribecommands to GA.
Kubernetes Engine
- Added
KCP_VPAoption to--loggingflag ofgcloud container clusters createto enable VPA Decision Logs feature. - Added
KCP_VPAoption to--loggingflag ofgcloud container clusters create-autoto enable VPA Decision Logs feature. - Added
KCP_VPAoption to--loggingflag ofgcloud container clusters updateto enable VPA Decision Logs feature. - Added node config options
nodeVfioConfigtogcloud container clusters create,gcloud container node-pools create, andgcloud container node-pools updatecommand which contains VFIO-related configurations for this node. - Added node config options
diskIoSchedulertogcloud container clusters create,gcloud container node-pools create, andgcloud container node-pools updatecommand which contains the configuration for the disk IO scheduler. - Promoted Rollbackable Upgrades (Two-Step Upgrades) to GA. Added
--control-plane-soak-durationflag togcloud container clusters upgradeand promotedgcloud container clusters complete-control-plane-upgradeto GA. - Promoted
--managed-otel-scopeflag to GA ingcloud container clusters createto enable Managed OpenTelemetry feature. - Promoted
--managed-otel-scopeflag to GA ingcloud container clusters create-autoto enable Managed OpenTelemetry feature. - Promoted
--managed-otel-scopeflag to GA ingcloud container clusters updateto enable Managed OpenTelemetry feature. - Additional kubectl versions:
- kubectl.1.30 (1.30.14)
- kubectl.1.31 (1.31.14)
- kubectl.1.32 (1.32.13)
- kubectl.1.33 (1.33.13)
- kubectl.1.34 (1.34.9)
- kubectl.1.35 (1.35.6)
- kubectl.1.36 (1.36.2)
Looker
- Promoted
--release-channeland--accelerated-security-patch-enabledflags to GA forgcloud looker instances createandgcloud looker instances update. - Added
RELEASE_CHANNELandACCELERATED_SECURITY_PATCH_ENABLEDcolumns togcloud looker instances describeoutput in GA track.
Network Security
- Added support for project-level security profiles to
gcloud network-security security-profiles wildfire-analysiscommands in BETA.
Transfer
- Deprecated
--s3-compatible-modeflag ingcloud transfer agents install. It is no longer needed as Transfer Service automatically detects S3-compatible job.
Vmware Engine
- Updated
gcloud vmware private-clouds createcommand to use full resource names for--preferred-zoneand--secondary-zoneflags when creating a stretched private cloud. This update ensures compliance with VPC Service Controls.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
575.0.1 (2026-07-07)
Google Cloud CLI
- Updated Windows bundled Python for the
gcloudCLI to 3.14.6 to resolve CVE-2026-34182.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
575.0.0 (2026-06-30)
Google Cloud CLI
- Added
any-reservation-then-failargument for flag--reservation-affinityingcloud container clusters node-pools create.
Agent Registry
- Added
gcloud agent-registrycommand group to manage Agent Registry resources.
AlloyDB
- Added
--failoverflag togcloud beta alloydb clusters promoteto support cross-region failover.
Apigee
- Added
gcloud apigee apis importwhich allows customers to upload API Proxy bundles in archive ZIP or feature template YAML format.
Artifact Registry
- Expose the Registry URL in the output of
gcloud artifacts repositories describeand in the output ofgcloud artifacts repositories create(upon synchronous creation).
Assured Workloads
- Added
SWITZERLAND_DATA_BOUNDARY_WITH_ACCESS_JUSTIFICATIONSoption to--compliance-regimeflag ofgcloud assured workloads create.
BigLake
- Added
gcloud biglake hive tables createto beta.
Cloud Access Context Manager
- Exposed
--service-accountand--service-account-project-numberforgcloud access-context-manager cloud-bindingscommands in the GA track.
Cloud Bigtable
- Added support for
--tagsflag togcloud bigtable instances createto allow binding tags on instance creation.
Cloud Data Lineage
- Added
gcloud datalineage processescommand group to manage data lineage processes.
Cloud Dataproc
- Added
--master-machine-typesflag ingcloud dataproc clusters create.
Cloud IAM
- Updated
gcloud iam service-accounts createto print the created service account's email address.
Cloud Run
- Made the
FILEpositional argument optional for allgcloud run * replacecommands, defaulting to their respective standard filenames if not specified. - Promoted regional inference to beta for Cloud Run services, jobs, and worker
pools. When
--regionor therun/regionproperty is not specified, the command line looks for a resource with that name in all regions. - Added
--sandbox-launcherflag togcloud beta run deployandgcloud beta run services updateto allow setting a container as sandbox launcher. - Promoted
--workdirflag forgcloud runcommands to GA. - Promoted interactive project prompt when project is not specified in
gcloud run deployto GA. - Promoted suggesting project and region from Artifact Registry URL in
gcloud run deployto GA. - Added
--tailflag togcloud beta run jobs executeto tail logs of the running execution. - Added
--dry-runflag togcloud beta run deploy,gcloud beta run services update,gcloud beta run services delete,gcloud beta run worker-pools deploy,gcloud beta run worker-pools update, andgcloud beta run worker-pools deleteto validate configuration without persisting changes. - Added
gcloud run jobs executions describe-latestcommand to describe the latest execution of a job. - Call out proxy when deploying or updating services with
gcloud run deployorgcloud run services updatethat require authentication in all tracks.
Cloud SQL
- Added
--userand--password-secret-versiontogcloud sql instances execute-sql.
Cloud Storage
- Added download validation via MD5 hash and checksumming for streaming downloads in
gcloud storage cp,gcloud storage mvandgcloud storage catcommands, see https://docs.cloud.google.com/storage/docs/streaming-downloads. - Updated
gcloud storage cpcommand to support streaming uploads with objects in RAPID storage see https://docs.cloud.google.com/storage/docs/streaming-uploads. - Updated
gcloud storage cpandgcloud storage mvcommands to support streaming downloads with objects in RAPID storage see https://docs.cloud.google.com/storage/docs/streaming-downloads. - Updated
gcloud storage catto support Rapid Bucket see https://docs.cloud.google.com/storage/docs/rapid/rapid-bucket.
Cloud Workstations
- Promoted
--pd-disk-sizeflag ofgcloud workstations updateto GA.
Cluster Director
- Users must supply a staticNodeCount if they want one. This no longer defaults to 1.
Compute Engine
- Added
gcloud alpha compute instance-groups managed configure-accelerator-topologiescommand to configure accelerator topologies of a managed instance group. - Added
gcloud compute instances set-machine-resourcescommand to allow setting machine resources for a virtual machine instances in alpha, beta, and GA. - Added
test-iam-permissionscommand togcloud compute storage-poolsto return permissions that a caller has on the specified storage pool. - Added
gcloud compute reservations sub-blocks set-iam-policycommand to beta and GA release tracks. - Added
gcloud compute reservations blocks set-iam-policycommand to set IAM policy on a reservation block in beta, preview, and GA. - Promoted support for
gcloud compute instance-groups managed resize-requests createfor regional MIG to GA. - Promoted support for
gcloud compute instance-groups managed resize-requests cancelfor regional MIG to GA. - Promoted support for
gcloud compute instance-groups managed resize-requests deletefor regional MIG to GA. - Promoted support for
gcloud compute instance-groups managed resize-requests describefor regional MIG to GA. - Promoted support for
gcloud compute instance-groups managed resize-requests listfor regional MIG to GA. - Added
gcloud compute instance-templates test-iam-permissionscommand to test IAM permissions on an instance template in alpha, beta, GA, and preview. - Added
gcloud compute target-https-proxies set-quic-overridecommand in beta, preview, and GA. - Added
gcloud compute reservations test-iam-permissionsto test IAM permissions on Compute Engine reservations. - Added
gcloud compute network-attachments set-iam-policycommand to set IAM policy on a network attachment in alpha, beta, preview, and GA. - Added
gcloud compute instances list-referrerscommand to alpha, beta, and GA release tracks. - Added
gcloud compute reservations blocks test-iam-permissionscommand to test IAM permissions on a reservation block in beta. - Added
gcloud compute interconnects attachments groups test-iam-permissionscommand to test IAM permissions on an interconnect attachment group in beta, preview, and GA. - Added support for displaying dynamic fields (such as
TERMINATION_TIMESTAMP) togcloud compute instance-groups managed list-instancesin GA.
Database Migration
- Added
--source-database-name-overrideflag togcloud database-migration conversion-workspaces seed|updateto allow overriding the database name for the seed operation.
GKE Hub
- Promoted
gcloud container fleet rolloutsto GA. - Promoted
gcloud container fleet rolloutsequencesto GA.
Kpt
- Updated kpt to v1.0.0-beta.64. See https://github.com/kptdev/kpt/releases/tag/v1.0.0-beta.64 for more details.
Kubernetes Engine
- Promoted GKE custom image flags (
--imageand--image-project) to GA, making them publicly visible ingcloud container clusters create,gcloud container clusters create-auto, andgcloud container node-pools create(and--image/--image-projectingcloud container clusters upgrade). - Added
stack-typeoption to--additional-node-networkflag ofgcloud container node-pools createto configure the stack type (ipv4,ipv4-ipv6, oripv6) for additional network interfaces.
Network Management
- Added
--source-cloud-run-jobflag togcloud network-management connectivity-tests.
Network Services
- Updated
gcloud edge-cache servicesimport schemas to support specifying up to 100 allowed origins inCORSPolicy.allowOriginsand a client TTL of0sinCDNPolicy.clientTtl.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
574.0.0 (2026-06-23)
AI Platform
- Added
gcloud beta ai semantic-governance-policy-engine deprovisioncommand to tear down a semantic governance policy engine, including its tenant project, GKE cluster, and PSC service attachments.
Agent Identity
- Added
gcloud beta agent-identity auth-providers get-iam-policy|set-iam-policy|add-iam-policy-binding|remove-iam-policy-binding|test-iam-permissionscommands.
Agent Registry
- Added
gcloud agent-registrycommand group to manage Agent Registry resources.
Backup For GKE
- Made
gcloud container backup-restorecommand groups compatible with non-default universe domains.
BigQuery
- Fixed a bug where
stderrmessages fromgcloudCLI output would be printed tostdout. - Added
--gcloud_config_cacheflag to enable caching data retrieved from thegcloudCLI. - Added display of container request concurrency of BigQuery Python UDF in
bq show --routine. - Added information about AI Agent in the execution environment to the user-agent HTTP header in the API request.
Cloud Datastream
- Added Regional Endpoints (REP) support for all Datastream commands.
Cloud Memorystore
- Added
--zone-distribution-config-zonesflag togcloud memorystore instances createcommand. This flag lets users specify multiple zones when they create aMULTI_ZONEcluster. - Added
--zone-distribution-config-zonesflag togcloud redis clusters createcommand. This flag lets users specify multiple zones when they create aMULTI_ZONEcluster.
Cluster Director
- Added support for creating clusters using
--quickstart-clusteringcloud beta cluster-director clusters create.
Colab
- Added Hyperdisk options to
--disk-typeofgcloud colab runtime-templates create:HYPERDISK_BALANCED.
Compute Engine
- Fixed an issue where
gcloud compute url-maps importreset customtimeoutandretryPolicy(specificallynumRetries) values to defaults when updating an existing URL map. - Added
--vsock-modeflag togcloud compute instances create,gcloud compute instance-templates create,gcloud compute instances bulk create, andgcloud compute queued-resources createin ALPHA to support enabling/disabling VSOCK mode. - Promoted
--purposeflag togcloud compute public-delegated-prefixes createin beta.
Database Migration
- Added Regional Endpoints (REP) support for all Database Migration Service (DMS) commands.
Kubernetes Engine
- Updated default kubectl from 1.35.3 to 1.35.6.
- Added new kubectl version 1.36.2 for the RAPID channel.
- Additional kubectl versions:
- kubectl.1.30 (1.30.14)
- kubectl.1.31 (1.31.14)
- kubectl.1.32 (1.32.13)
- kubectl.1.33 (1.33.13)
- kubectl.1.34 (1.34.9)
- kubectl.1.35 (1.35.6)
- kubectl.1.36 (1.36.2)
Network Security
- Promoted
gcloud network-security ull-mirroring-enginesandgcloud network-security ull-mirroring-collectorscommands to beta. - Promoted
gcloud network-security ull-mirroring-enginesandgcloud network-security ull-mirroring-collectorscommands to GA.
Subscribe to these release notes at https://groups.google.com/forum/#!forum/google-cloud-sdk-announce.
573.0.0 (2026-06-16)
Breaking Changes
- (Anthos Multi-Cloud) Deprecated
gcloud container attached clusters get-credentials. Usegcloud container fleet memberships get-credentialsto get credentials for a running Attached cluster.
Google Cloud CLI
- Updated Windows bundled Python for the
gcloudCLI to 3.14.5.
AI
- Added
gcloud ai tuning-jobscommand group to manage Vertex AI supervised fine-tuning jobs.
App Engine
- Updated the Java SDK to version 5.0.4 build from the open source project https://github.com/GoogleCloudPlatform/appengine-java-standard/releases/tag/v5.0.4.
- fixed https://github.com/GoogleCloudPlatform/appengine-java-standard/issues/506.
Artifact Registry
- Added
gcloud artifacts image-streaming-cachecommand group to manage image streaming caches per region. This group includescreate,describe,delete, andlistcommands.
BigLake
- Promoted
--unity-service-principal-application-idflag forgcloud biglake iceberg catalogs createandupdateto BETA, making it publicly visible. - Promoted BigLake catalogs and arguments for
gcloud biglake iceberg catalogsto GA.
Cloud Data Lineage
- Added
gcloud datalineagecommand group to manage Cloud Data Lineage resources. - Added
gcloud datalineage config describeandgcloud datalineage config updatecommands to manage Data Lineage configurations.
Cloud Datastream
- Added support for Dataverse, Salesforce Marketing Cloud, and ServiceNow connection profiles to
gcloud datastream connection-profiles createandupdatecommands. - Added support for Dataverse, Salesforce Marketing Cloud, and ServiceNow streams to
gcloud datastream streams createandupdatecommands.
Cloud Run
- Promoted
--readiness_probeingcloud run deployandgcloud run services updateto GA.
Cloud Services
- API Keys: Updated
gcloud services api-keyscreateandupdatecommands'--api-targetflag to accept a colon-separated list ofmethodsinline (e.g.--api-target="service=foo,methods=m1:m2").
Cloud Storage
- Promoted
gcloud storage batch-operations bucket-operationscommands to GA.
Cluster Director
- Added support for creating clusters using blueprints in
gcloud beta cluster-director clusters create.
Compute Engine
- Promoted
--action-on-vm-failed-health-checkflag to GA forgcloud compute instance-groups managed createandgcloud compute instance-groups managed update. - Fixed an issue where waiting for asynchronous operations would fail for certain global nested resources (like