You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
August 27, 2026
For regional external passthrough Network Load Balancers, reserving specific or automatically allocated bring your own IP (BYOIP) IPv6 addresses before creating a load balancer, and promoting an ephemeral BYOIP IPv6 address in use by a load balancer to a reserved static IP address, is generally available (GA).
For more information, see the following documentation:
August 26, 2026
SSL policy cross-project referencing is now available for Application Load Balancers and proxy Network Load Balancers in Preview. You can use cross-project referencing to define and maintain a central SSL policy in an administrative project and reference it from target HTTPS proxies or target SSL proxies in different projects.
Cross-project referencing is supported for global and regional SSL policies. You can use cross-project referencing with the following load balancers:
- Global external Application Load Balancer
- Regional external Application Load Balancer
- Cross-region internal Application Load Balancer
- Regional internal Application Load Balancer
- Global external proxy Network Load Balancer
For more information, see Cross-project SSL policy referencing.
August 19, 2026
Global Front End combines global external Application Load Balancers, Google Cloud Armor, Cloud CDN, and Service Extensions into one solution to help deliver, scale, and secure your internet-facing applications.
For more information, see Global Front End.
This feature is available in Preview.
August 04, 2026
Regular expression URL rewrites (regexRewrite) for route rules in URL maps are
now available for Application Load Balancers. You can use regular expression
pattern rewrite actions to rewrite URL paths by substituting or removing URL
path components before forwarding requests to your backends.
For more information, see Regular expression URL rewrites for route rules.
This feature is in Preview.
July 31, 2026
Cloud Load Balancing introduces a new version of the Network Load Balancer—the global external passthrough Network Load Balancer, which is the global variant of the regional external passthrough Network Load Balancer. The load balancer is available in Preview.
This load balancer variant solves use cases for Security Service Edge (SSE), DNS hosting, Adtech (real-time bidding), real-time communications (RTC), live streaming, and online gaming, among others.
Global external passthrough Network Load Balancers are Layer 4 passthrough load balancers that distribute external traffic among backends (instance groups or network endpoint groups) that can reside in multiple Google Cloud regions. By using Google's global anycast IP routing, the global external passthrough Network Load Balancer steers user traffic to the closest region with healthy backends and available capacity, delivering ultra-low latency and dynamic cross-region failover to ensure resilience to regional outages.
The load balancer provides you with two external IP addresses, each served by a disjoint and isolated global load balancing control and data plane server infrastructure (also known as an availability group) to provide high availability.
The load balancer supports TCP, UDP, ESP, GRE, ICMP, and ICMPv6 traffic and can handle both IPv4 and IPv6 traffic. You can deploy your backends in any of the following Google Cloud regions:
- North America:
us-west1,us-west4,us-east4,us-east5 - Europe:
europe-west2,europe-west3 - Asia:
asia-southeast1,asia-south1,asia-northeast1 - South America:
southamerica-east1 - Africa:
africa-south1 - Australia:
australia-southeast1
Note that this release doesn't support GKE backends for the global external passthrough Network Load Balancer.
For details on the new load balancer, see Global external passthrough Network Load Balancer overview.
July 27, 2026
Service load balancing policies (serviceLbPolicy) are now supported for
regional external Application Load Balancers and regional internal Application Load Balancers. This feature enables
advanced load balancing optimizations such as custom load balancing algorithms,
auto-capacity draining, failover thresholds, and the ability to designate
preferred backends for these load balancers.
For more information, see Advanced load balancing optimizations.
This feature is in Preview.
July 20, 2026
For regional external passthrough Network Load Balancers, you can reserve specific or automatically allocated bring your own IP (BYOIP) IPv6 addresses before creating a load balancer, so that the IPv6 address persists independently of the load balancer's lifecycle. You can also promote an ephemeral BYOIP IPv6 address that is in use by a load balancer to a reserved static IP address.
For more information, see the following documentation:
- Set up a regional external passthrough Network Load Balancer with a backend service.
- Set up a regional external passthrough Network Load Balancer for multiple IP protocols
- Set up a regional external passthrough Network Load Balancer with zonal NEGs
This feature is in Preview.
June 30, 2026
Regular expressions matchers in host and route rules in URL maps
You can now use regular expressions to configure more flexible and precise traffic routing rules within URL maps for Global external Application Load Balancers.
This feature lets you leverage the power of RE2 syntax for matching on:
- Route rules: Within
pathMatchers, thematchRulesarray now supports aregexMatchfield to validate the URL path against a specified regex pattern. - Header matches: Within
matchRules, theheaderMatchesarray now supports aregexMatchfield for pattern matching against HTTP header values. - Query parameter matches: Within
matchRules, thequeryParameterMatchesarray now supports aregexMatchfield for pattern matching against HTTP query parameters values.
For more details on usage and syntax, see URL map concepts: Regular expressions matchers in host and route rules.
This feature is in Preview.
June 02, 2026
TLS post-quantum key exchange support is now available for
Application Load Balancers and external proxy Network Load Balancers.
Post-quantum key exchange is
essential for protecting today's traffic from future quantum computing
decryption risks (harvest now, decrypt later attacks).
With post-quantum key exchange enabled, the
load balancer uses post-quantum key exchange with clients that support TLS
1.3 and X25519MLKEM768 key exchange.
This feature is rolling out in three phases:
Phase 1 (Until October 2026): Post-quantum key exchange is not enabled by default. Customers can elect to opt in and enable it using their SSL policy.
Phase 2 (October 2026 through October 2027): The feature is enabled by default. Customers can elect to defer (opt out) if required.
Phase 3 (After October 2027): The feature is enabled by default, and options to defer are no longer effective.
We strongly encourage you to enable post-quantum key exchange now, even before it is turned on by default. The opportunity to test this today will help you verify that clients and any intermediate network devices can properly negotiate post-quantum key exchange.
For more information, see Post-quantum key exchange.
June 01, 2026
A modernized, component-centric interface for Cloud Load Balancing is available in Preview. This inaugural release provides an expanded perspective of load balancing infrastructure, offering enhanced transparency into individual component configurations.
The key features of this release include the following:
Comprehensive resource inventory: A centralized, searchable, and sortable management layer for granular resources—including forwarding rules, target proxies, and TLSRoutes—facilitating detailed monitoring of resource status and interdependencies.
Interactive resource topology: A contextual visualization tool that maps traffic flow from forwarding rules through proxies to backends, enabling technical teams to efficiently analyze dependencies and accelerate issue resolution.
Integrated audit logging: Embedded audit logs within the console that offer a unified module for monitoring and tracking historical configuration changes.
May 26, 2026
For global external Application Load Balancers, you can configure Cloud CDN cache policies at various levels of a URL map. This provides granular control over caching policies based on criteria like hostname, URL path, HTTP headers, and query parameters. This feature is in General availability.
For more information, see Configure a Cloud CDN cache policy.
Frontend configuration for load balancing incoming IPv6 traffic is now supported for the following load balancers:
- Regional external Application Load Balancer
- Regional external proxy Network Load Balancer
- Regional internal Application Load Balancer
- Regional internal proxy Network Load Balancer
- Cross-region internal Application Load Balancer
- Cross-region internal proxy Network Load Balancer
This feature is in Preview.
For more information, see the following documentation:
May 22, 2026
Application Load Balancers now support the configuration of a
traffic duration
setting when you add backends to backend services. You can configure this
setting as SHORT or LONG based on the response time needed by backends to
complete HTTP requests.
Application Load Balancers also support the use of the in-flight balancing mode that lets you configure the load balancer's traffic distribution to supported backends when requests take more than a second to complete.
This feature is in General availability.
May 21, 2026
Zonal affinity, which was previously available in Preview, is generally available (GA).
For more information, see Zonal affinity for internal passthrough Network Load Balancers.
May 19, 2026
Google tag gateway for advertisers lets website owners host and deploy Google tags through Google Cloud. You can use a global external Application Load Balancer to route measurement traffic on your website through your domain for improved measurement data accuracy. This provides more reliable data for advertising campaign optimization.
For more information, see Google tag gateway for advertisers.
May 14, 2026
You can use three new variables in custom request and response headers for Application Load Balancers:
asn: The Autonomous System Number (ASN) associated with the client's IP address.cloud_trace_id: The trace ID extracted (or generated) from the HTTP request header.hostname: The original hostname specified by the client in theHostHTTP request header. This allows preservation of the original host header (equivalent toX-Forwarded-Host).
These variables are available for both global external Application Load Balancers and classic Application Load Balancers.
For more information, see Create custom headers in backend services.
April 30, 2026
Backend Cloud Storage buckets are available for regional external Application Load Balancers and regional internal Application Load Balancers.
For more information, see:
- Set up a regional external Application Load Balancer with Cloud Storage buckets
- Set up a regional internal Application Load Balancer with Cloud Storage buckets
- Set up a regional external Application Load Balancer with Cloud Storage buckets in a Shared VPC environment
- Set up a regional internal Application Load Balancer with Cloud Storage buckets in a Shared VPC environment
This feature is in General availability.
April 27, 2026
A new quota system governing the configuration size of Application Load Balancer is now available in Preview. This update increases the individual URL map size limit from 64 KB and 128 KB to 1 MB. For more information, see URL map size and quota units.
Key aspects of this feature include:
- Complexity-based quota: Quota units reflect URL map complexity (number of rules, hostnames, and path matchers).
- Scoped measurement: Quota is measured and enforced on a per-project, per-region, or per-VPC depending on Application Load Balancer type.
- Active consumption: Only URL maps currently referenced by forwarding rules contribute to quota usage.
- New URL map size limit: Projects enabled for the new quota have a new URL map size limit increased to 1 MB for global and regional external and internal Application Load Balancers. Classic Application Load Balancer remain restricted to 64 KB.
For more information on increasing your limit or to participate in the preview, please contact Google Cloud Support.
April 22, 2026
Policy profiles in authorization policies let you define the type of authorization being performed at the load balancer. This feature is available in Preview.
You can choose from the following profile types:
Request authorization profile (
REQUEST_AUTHZ): Evaluates access based on HTTP request headers. Authorization decisions can be made directly or delegated to custom services. This is the default profile.Content authorization profile (
CONTENT_AUTHZ): Enables deep inspection of application payloads (headers, body, and trailers). This is used for content-based security, such as blocking prompt injection attacks and preventing sensitive data leaks. Authorization decisions are always delegated.
Policy profiles are supported for the following Google Cloud services:
- Regional external Application Load Balancers
- Regional internal Application Load Balancers
- Agent Gateway (Preview)
- Secure Web Proxy
To learn more about policy profiles, see Authorization policy overview.
April 10, 2026
Published service backends let you configure supported load balancers or regional Cloud Service Mesh to route traffic to published services through Private Service Connect endpoints.
For more information, see Published service backends.
This feature is in Preview.
April 05, 2026
Certificate Manager certificates are available in Google Cloud console while provisioning a load balancer.
You can select a certificate map for the following load balancers:
- Global external Application Load Balancers
- Classic Application Load Balancers
- Global external proxy Network Load Balancers
- Classic proxy Network Load Balancers
You can select a Certificate Manager certificate for the following load balancers:
- Regional external Application Load Balancers
- Regional internal Application Load Balancers
- Cross-region internal Application Load Balancers
This feature is in General availability.
March 31, 2026
SNI-based routing for proxy Network Load Balancers is now available in Preview.
You can now route TLS traffic based on Server Name Indication (SNI) hostnames
by using the new TLSRoute resource. The load balancer inspects the
initial unencrypted ClientHello message to extract the SNI hostname and
route connections to the appropriate backend service.
This feature provides pure TLS passthrough without terminating the connection
at the load balancer. Key benefits include:
- End-to-end encryption: Clients can establish secure mTLS or TLS sessions directly with origin servers.
- Role-oriented management: The
TLSRouteAPI lets platform administrators to manage frontend infrastructure while service owners manage their own routes and backends independently. - Simplified IP management: Consolidate multiple services behind a single Private Service Connect (PSC) endpoint, reducing IPv4 address exhaustion.
This feature is available for regional and cross-region proxy Network Load Balancers.
For more information, see:
February 24, 2026
Backend Cloud Storage buckets are available for regional external Application Load Balancers, regional internal Application Load Balancers, and cross-region internal Application Load Balancers in a Shared VPC environment.
Support for this feature is available in Preview for regional external Application Load Balancers and regional internal Application Load Balancers and in General availability for cross-region internal Application Load Balancers. For more information, see:
- Set up a regional external Application Load Balancer with Cloud Storage buckets in a Shared VPC environment
- Set up a regional internal Application Load Balancer with Cloud Storage buckets in a Shared VPC environment
- Set up a cross-region internal Application Load Balancer with Cloud Storage buckets in a Shared VPC environment
February 23, 2026
Backend mutual TLS (mTLS) and backend authenticated TLS is now Generally available for cross-region internal Application Load Balancers.
This update complements existing support for global and regional Application Load Balancers, allowing you to enforce bidirectional identity verification across your regional deployments.
For details, see the following:
January 28, 2026
To enhance security and help meet stringent compliance requirements like FedRAMP, you can now apply a FIPS-compliant SSL policy to your Application Load Balancers and proxy Network Load Balancers. This update also introduces the ability to enforce TLS 1.3 as the minimum protocol version.
New FIPS_202205 profile
The new FIPS_202205 profile, available as a predefined SSL policy, restricts
the load balancer to use only FIPS 140-2/140-3 validated cryptographic modules
and ciphers.
When this profile is selected, the load balancer:
- Enforces strict TLS settings, negotiating connections only using TLS 1.2 or TLS 1.3.
- Uses a limited set of approved cipher suites for TLS 1.2,
such as the cipher suites in
ECDHE-RSA-AES-GCMandECDHE-ECDSA-AES-GCMfamilies. - Excludes non-FIPS ciphers for TLS 1.3, such as
TLS_CHACHA20_POLY1305_SHA256.
Minimum TLS 1.3 Enforcement
You can now specify TLS 1.3 as the minimum version for your SSL policy, which
must be paired with the RESTRICTED profile. If you mandate TLS 1.3 as the
minimum version, any clients attempting to connect via TLS 1.2 or lower will be
rejected. Ensure your client ecosystem supports TLS 1.3 before enforcing this
minimum TLS version.
For more information, see the following:
This feature is in General availability.
January 23, 2026
Application Load Balancers now support the configuration of a
traffic duration
setting when you add backends to the backend services. You can configure this
setting as SHORT or LONG based on the response time needed by backends to
complete HTTP requests.
Application Load Balancers also support the use of a new in-flight balancing mode that lets you configure the load balancer's traffic distribution to supported backends when requests take more than a second to complete.
This feature is available in Preview.
January 19, 2026
Backend buckets are available for regional external Application Load Balancers and regional internal Application Load Balancers.
This feature enables to serve static content (such as images, video, and CSS) confined to a specific region, helping you meet strict data residency and compliance requirements for regulated workloads. This update ensures backend bucket availability across the entire Application Load Balancers portfolio.
For more information, see the following:
- Set up a regional external Application Load Balancer with Cloud Storage buckets
- Set up a regional internal Application Load Balancer with Cloud Storage buckets
This feature is in Preview.
January 16, 2026
Managed workload identity is available for backend mutual TLS (mTLS) in global external Application Load Balancers.
This feature allows to:
Streamline certificate management: Managed workload identity enables automated certificate and trust management for backend mTLS through seamless integration with Certificate Authority Service and Certificate Manager.
Eliminate operational toil: Certificates are automatically rotated based on the workload identity pool's configuration, removing the complexity and manual bottleneck of private key provisioning and maintenance.
Improve visibility and governance: Gain visibility into communication between distributed services and proactively apply governance to workloads across environments.
For more information, see Backend mTLS with managed workload identity overview
This feature is in Preview.
December 17, 2025
Starting December 17, 2025, requests with request methods that aren't compliant with RFC 9110, Section 5.6.2 will be rejected by a first-layer Google Front End (GFE) before reaching your load balancer or its backends. Previously, such non-compliant requests would have been rejected by the load balancer or its backends with a variety of error codes. With the GFE now handling such requests, you might observe a small decrease in error rates.
This change applies only to global external Application Load Balancers and classic Application Load Balancers.
December 03, 2025
Regular expressions matchers in host and route rules in URL maps
You can now use regular expressions to configure more flexible and precise traffic routing rules within URL maps for Application Load Balancer. This feature lets you leverage the power of RE2 syntax for matching on:
- Route rules: Within
pathMatchers, thematchRulesarray now supports aregexMatchfield to validate the URL path against a specified regex pattern. - Header matches: Within
matchRules, theheaderMatchesarray now supports aregexMatchfield for pattern matching against HTTP header values. - Query parameter matches: Within
matchRules, thequeryParameterMatchesarray now supports aregexMatchfield for pattern matching against HTTP query parameters values.
This feature is available for the following load balancers:
- Regional internal Application Load Balancer
- Cross-region internal Application Load Balancer
- Regional external Application Load Balancer
For more details on usage and syntax, see URL map concepts: Regular expressions matchers in host and route rules.
This feature is in Preview.
December 02, 2025
Backend mutual TLS (mTLS) and backend authenticated TLS are now Generally available for the following regional Application Load Balancers:
- Regional external Application Load Balancers
- Regional internal Application Load Balancers
This update complements existing support for global external Application Load Balancers, allowing you to enforce bidirectional identity verification across your regional deployments.
For details, see the following:
November 04, 2025
GRPC_WITH_TLS health checks are used for health checking gRPC backends
with TLS enabled. For more information, see the following:
This feature is in General availability.
October 31, 2025
The global and classic external Application Load Balancers implemented on Google Front-Ends (GFEs) now reject TLS connections when the client and the load balancer support ALPN (Application-Layer Protocol Negotiation), but don't share common ALPN protocols.
Previously, if a client proposed a list of application protocols during the TLS
handshake using the ALPN extension and none were supported by the load balancer,
ALPN would be deactivated and the connection would default to using HTTP/1 as
the default application protocol. After this update, the GFE instead returns
an SSL_TLSEXT_ERR_ALERT_FATAL response which causes the load balancer to
terminate the TLS handshake, and the connection to close. This change ensures
that an application-layer protocol is always explicitly negotiated between the
clients and the load balancers that support ALPN.
October 29, 2025
You can specify a custom ephemeral /96 IPv6 address range when creating a
regional IPv6 forwarding rule. For more information, see the following:
- Internal passthrough Network Load Balancer overview
- Backend service-based external passthrough Network Load Balancer overview
- Protocol forwarding overview
This feature is in General availability.
October 28, 2025
Both internal passthrough Network Load Balancers and external passthrough Network Load Balancers support load balancing to managed instance groups (MIGs) comprised of IPv6-only VM instances.
For more details, see the following pages:
- Set up an external passthrough Network Load Balancer with a backend service
- Set up an internal passthrough Network Load Balancer with VM instance group backends
This feature is in General availability.
Application Load Balancers support authorization policies that let you establish access control checks for incoming traffic.
For details, see Authorization policy overview.
This feature is in General availability.
October 06, 2025
Percentage-based request mirroring is now supported for the global and regional external Application Load Balancers (classic is not supported). By default, the mirrored backend service receives all requests, even if the original traffic is being split between multiple weighted backend services. You
can now configure the mirrored backend service to receive only a percentage of the
requests by using the mirrorPercent flag to specify the percentage of
requests to be mirrored, expressed as a value between 0 and 100.0.
For an example, see Set up traffic management for regional external Application Load Balancers.
This feature is available in General availability.
September 17, 2025
A security fix was made which changes the behavior of requests and responses sent with the Transfer-Encoding: Chunked header to be more RFC 9112 compliant. The RFC states that both the chunked_body and the last-chunk fields must end in CRLF. This is now enforced.
September 12, 2025
The global and classic external Application Load Balancers implemented on Google Front-Ends (GFEs) now support HTTP/1.0 explicitly as a protocol during ALPN (Application-Layer Protocol Negotiation) negotiation.
Previously, when the GFEs didn't support HTTP/1.0 explicitly, the GFE would return an SSL_TLSEXT_ERR_NOACK response, disable ALPN, and fall back to using HTTP/1 (which includes HTTP/1.0 and HTTP/1.1) as the default application protocol. After this change, GFEs will instead return HTTP/1.0, which provides clients with positive confirmation that their advertised HTTP/1.0 was accepted.
You are not expected to make any changes with this update. If a TLS handshake with HTTP/1.0 is unsuccessful, please contact support.
August 26, 2025
The internal and external passthrough Network Load Balancers now support load balancing to unmanaged instance groups comprised of IPv6-only VM instances.
Protocol forwarding also supports IPv6-only target instances.
For more details, see the following pages:
- Protocol forwarding overview
- Backend service-based external passthrough Network Load Balancer overview
- Internal passthrough Network Load Balancer overview
- Set up an internal passthrough Network Load Balancer with IPv6-only subnets and backends
This feature is available in General Availability.