Anthos Config Management
Changed
Config Sync now supports the client.lifecycle.config.k8s.io/mutation: ignore annotation for compatibility with other controllers. This enhancement provides more consistent behavior and correctly reports the resource status.
Changed
Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.
Announcement
You can now control the scheduling of Config Sync pods using the Kubernetes-native resource MutatingAdmissionPolicy. For more information, see Customize node placement of Config Sync system pods to get started.
Changed
Config Sync’s internal observability library has been updated from OpenCensus to OpenTelemetry, improving performance and aligning with industry standards with no breaking changes to metrics or functionality.
Apigee X
Feature
Mask KVM values
You can now turn on key value map (KVM) masking to mask values with asterisks (*****). For more information, see About KVM masking.
Cloud Service Mesh
Announcement
Managed Cloud Service Mesh will start using proxy version
csm_mesh_proxy.20251121c_RC00 for Gateway API on GKE clusters. This proxy
version maps closest to Envoy version 1.37. This change is rolling out to all
release channels and contains the fix for the managed Cloud Service Mesh
security vulnerability listed in [GCP-2025-073](/service-mesh/docs/security-bulletins#gcp-2025-073.
Dataproc
Announcement
Serverless for Apache Spark: Runtime version 3.0 is now generally available. This version simplifies onboarding, improves reliability, reduces startup latency, and adds support for Spark 4.0.
Features and improvements:
- Regional and multi-zonal workloads are used by default to increase obtainability of compute resources
- Faster startup than previous runtimes
- Fast resource cleanup that allows faster release of VPC IPs after workload completion
- End-user credentials are used for all workloads by default
- New
bigquerySpark catalog, pre-configured for out-of-the-box BigQuery native table interactions - New Spark Serverless-specific IAM roles
- New
dataproc-rm.googleapis.comAPI enablement is required
Gemini
Feature
Model selection for VS Code Gemini Code Assist
The following VS Code Gemini Code Assist users can now manually select the model used by Gemini Code Assist:
- Gemini Code Assist Enterprise users
- Gemini Code Assist Standard users
- Gemini Code Assist for individuals, if you have a Google AI Pro or Ultra subscription
Feature
Model selection for VS Code Gemini Code Assist
The following VS Code Gemini Code Assist users can now manually select the model used by Gemini Code Assist:
- Gemini Code Assist Enterprise users
- Gemini Code Assist Standard users
- Gemini Code Assist for individuals, if you have a Google AI Pro or Ultra subscription
Google SecOps Marketplace
Changed
CSV: Version 38.0
- Integration: Updated dependencies.
Changed
Tenable Security Center: Version 19.0
- Integration: Added support to authenticate using an Access Key and a Secret Key.
Changed
Cofense Triage: Version 15.0
Improved category based filtering in the following connector:
- Cofense Triage – Reports Connector
Changed
Gmail: Version 6.0
- Integration: Updated the dependency files.
Source: Google Cloud Platform





