Google Cloud Weekly - GCP Newsletter #326

Welcome to issue #326 December 26th, 2022

As this is the last issue in 2022, I want to thank you all for sticking with this newsletter, your feedback, and your support, and wish you all the best in 2023.

News

AI Document AI Official Blog

Document AI adds three new capabilities to its OCR engine - Announcing three new features for Document AI OCR, including intelligent document quality metrics, digital PDF support, and OCR model versioning.

Google Kubernetes Engine Networking Official Blog

New control plane connectivity and isolation options for your GKE clusters - New GKE networking options enable cluster isolation for the control plane and node pools, for more scalable, secure, and cost-effective GKE clusters.

Cloud Filestore Google Kubernetes Engine Official Blog

Filestore Enterprise Multishares for GKE now generally available - Using Filestore Enterprise multishare with your GKE environment can improve storage efficiency.

Sponsor

Articles, Tutorials

Infrastructure, Networking, Security, Kubernetes

CISO Official Blog Security

Cloud CISO Perspectives: December 2022 - Which security lessons of the past year were the most important? We look back at 2022 with members of GCAT and Google Cloud’s Office of the CISO.

Cloud Load Balancing Networking Official Blog

Understanding Cloud Load Balancing for hybrid and multicloud environments - Cloud Load Balancing supports hybrid and multicloud with universal traffic management policies, and tools for high performance and reliability.

Networking Official Blog

An Introduction to IPv6 on Google Cloud - Google Cloud now supports IPv6 addressing on ‘dual-stack’ VM instances running both IPv4 and IPv6, as well as dual-stack GKE nodes and pods.

Cloud Armor Google Kubernetes Engine Kubernetes Security

Protecting GKE Ingress default backend with Cloud Armor - Learn how to protect the GKE Ingress default backend with Cloud Armor Policies.

Anthos Kubernetes Networking

The Benefits of Using MetalLB for Load Balancing in Google Anthos - Benefits of using Metal Load Balancer with Anthos.

Cloud Identity Infrastructure Networking

Setup SSO for OpenVPN Access Server with Google Cloud Identity using SAML - With OpenVPN Access Server 2.11 or above, you can set up SSO using SAML, this blog post describes setting up SSO with Google Cloud Identity.

Chronicle

The Chronicle CLI - Chronicle SIEM recently released the Chronicle CLI onto GitHub. In this post I’ll explore what it is, and how to start using it.

App Development, Serverless, Databases, DevOps

Cloud Build DevOps Official Blog Serverless

The Squire’s guide to automated deployments with Cloud Build - Getting started with your first automated deployment pipeline using open source project Emblem featuring Google Cloud Serverless products like Cloud Run, Cloud Build, Artifact Registry, and Pub/Sub.

Cloud Memorystore Official Blog

Google Cloud Memorystore for Redis Best Practices - Tips for a highly performant and worry-free deployment - Memorystore for Redis on Google Cloud is a fully managed, highly available, highly performing, scalable and secure service for Redis. Best practices & features that will accelerate your deployment.

BigQuery Cloud SQL Datastream

Configuring Google Cloud Datastream private connectivity with Cloud SQL for PostgreSQL - Running Datastream replicating data from a Cloud SQL PostgreSQL from another project with a private IP to BigQuery.

API Apigee

Best practices for architecting cost-effective and scalable Apigee-X PayG Organisation in GCP - A checklist for crucial decision areas that need to be planned before provisioning an Apigee X organization.

Apigee Monitoring Prometheus

BYOP — Bring your own Prometheus (and Grafana) to monitor Apigee hybrid - This article describes the deployment of a custom end-to-end metrics path based on the popular open-source tool Prometheus and Grafana for hybrid Apigee deployment.

Apigee Networking

How to globally expose Apigee for internal traffic - This article provides a step-by-step guide on how to leverage the “global-access” feature of the Internal Load Balancer to expose different API services within your organisation with a single entry point over multiple regions.

Cloud SQL Terraform

GCP Cloud SQL Users in Terraform - Setting users for Cloud SQL via Terraform.

Cloud Run Secret Manager

Cloud Run: Hot reload your Secret Manager secrets - Keep the latest secret version in Cloud Run with Secret Manager integration can be a challenge or even a blocker. But not anymore!

DevOps SRE

Disaster Recovery — locality-restricted workloads on GCP - This post discusses how you can use Google Cloud to architect for disaster recovery (DR) to meet location-specific requirements.

Big Data, Analytics, ML&AI

Apache Beam Cloud Dataflow

Dead letter queue for errors with Beam, Asgarde, Dataflow and alerting in real time - The goal of this article is showing a use case with a Beam pipeline containing a dead letter queue for errors applied with Asgarde library.

BigQuery

Data augmentation with BigQuery and Google Knowledge Graph - Example of using data from Google Knowledge Graph to enrich data in BigQuery.

Big Data BigQuery Data Science

How I use BigQuery Analytic Functions as a Data Scientist - Practical examples on how to use advanced SQL to do analyses in BigQuery.

BigQuery Data Science GIS

Loading Geographic Multiband Raster Data in BigQuery - Goal: Load Raster Data in BigQuery using Dataflow with GeoBeam or GDAL core libraries.

Data Analytics Official Blog R Vertex AI

Perform hyperparameter tuning using R and caret on Vertex AI - How to perform hyperparameter tuning on Vertex AI using custom containers for models written in R.

BigQuery Machine Learning

BigQuery View Table for Machine Learning Feature Store - Organizing data in BigQuery for Machine Learning.

Various

Google Cloud Platform Official Blog

2022 was a year spent turning sustainable ambitions into action - Enabling Google Cloud customers to make sustainability-minded decisions contributes to reversing climate change in a big way.

Google Cloud Platform Official Blog

The top 8 products startups use on Google Cloud - Discover the 8 top products that startups use on Google Cloud to innovate and grow.

Google Cloud Platform Official Blog

A motorcycle accident left Googler Yariv Adan with chronic pain—it’s made him an advocate for empathy and equity - Product Lead for Cloud Conversational AI, Yariv Adan shares how he’s breaking stigmas and advocating for disabled colleagues in the workplace.

Google Cloud Platform Official Blog

Google Cloud wrapped: Top 22 news stories of 2022, according to you - We ran the numbers to find this year’s top Google Cloud news stories, by readership.

GCP Certification

Passing all the 12 Google Cloud certifications efficiently - Comparing GCP certification exams.

Slides, Videos, Audio

GCP Podcast - #331 2022 Year End Wrap Up.

Security Podcast - #102 Sunil Potti on Building Cloud Security at Google.

Releases

Anthos clusters on AWS - A new vulnerability (CVE-2022-2602) has been discovered in the io_uring subsystem in the Linux kernel that can allow an attacker to potentially execute arbitrary code.

Anthos clusters on bare metal - 1.13 & 1.14. Anthos clusters on bare metal release 1.14.0 is now available for download. 1.13. Release 1.13.3 Anthos clusters on bare metal 1.13.3 is now available for download. The following container image security vulnerabilities have been fixed: CVE-2022-35737 CVE-2022-42311 CVE-2022-33745 CVE-2022-42309 CVE-2022-42320 CVE-2022-42323 CVE-2022-33748 CVE-2022-42321 CVE-2022-33746 CVE-2022-42310 CVE-2022-42316 CVE-2022-42322 CVE-2022-42319 CVE-2022-42325 CVE-2022-42315 CVE-2022-42324 CVE-2022-42314 CVE-2022-42317 CVE-2022-42312 CVE-2022-42318 CVE-2022-42313 CVE-2022-42326. Known issues: For information about the latest known issues, see Anthos on bare metal known issues in the Troubleshooting section.

Anthos clusters on Azure - A new vulnerability (CVE-2022-2602) has been discovered in the io_uring subsystem in the Linux kernel that can allow an attacker to potentially execute arbitrary code.

Anthos clusters on VMware - A new vulnerability (CVE-2022-2602) has been discovered in the io_uring subsystem in the Linux kernel that can allow an attacker to potentially execute arbitrary code. Anthos clusters on VMware 1.14.0-gke.430 is now available. Support for user cluster creation with Controlplane V2 enabled is now generally available. Upgraded Kubernetes from 1.24 to 1.25: Migrated PDB API version from policy/v1beta1 to policy/v1. Fixed an issue where anet-operator could be scheduled to a Windows node with enableControlplaneV2: true. Anthos clusters on VMware 1.12.4-gke.42 is now available. Changed the relative file path fields in the admin cluster configuration file to use absolute paths. Increased memory limit of monitoring-operator- Pods to 1 GB to avoid potential OOM events under certain configurations.

Anthos GKE on AWS - A new vulnerability (CVE-2022-2602) has been discovered in the io_uring subsystem in the Linux kernel that can allow an attacker to potentially execute arbitrary code.

AppEngine Standard - The option to update a Serverless VPC Access connector is now available in preview.

Batch - Documentation has been updated to include new samples.

BigQuery - The Lineage tab in the table properties page lets you track how your data moves and transforms through BigQuery. BigQuery now blocks saving query results to Google Drive from projects inside a VPC Service Controls protected perimeter.

Cloud Composer - (Available without upgrading) Fixed an issue where upgrading a Private IP environment with VPC peerings to Cloud Composer 2.0.31 and later versions resulted in intermittent issues with database connections. Cloud Composer 1.20.2 and 2.1.2 are versions with an extended upgrade timeline.

Compute Engine - Generally available: N2 VMs with 64 or more vCPUs now support up to 4 GB/s (read) and 3 GB/s (write) throughput per instance with Extreme persistent disks (pd-extreme).

Dataproc Serverless - New sub-minor versions of Dataproc images: 1.5.79-debian10, 1.5.79-rocky8, 1.5.79-ubuntu18 2.0.53-debian10, 2.0.53-rocky8, 2.0.53-ubuntu18 2.1.1-debian11, 2.1.1-rocky8, 2.1.1-ubuntu20. New Dataproc Serverless for Spark runtime versions: 1.0.25 2.0.5. Backported Spark patch in Dataproc Serverless for Spark runtime 1.0 and 2.0: SPARK-40481: Ignore stage fetch failure caused by decommissioned executor.

Dataproc - New sub-minor versions of Dataproc images: 1.5.79-debian10, 1.5.79-rocky8, 1.5.79-ubuntu18 2.0.53-debian10, 2.0.53-rocky8, 2.0.53-ubuntu18 2.1.1-debian11, 2.1.1-rocky8, 2.1.1-ubuntu20. New Dataproc Serverless for Spark runtime versions: 1.0.25 2.0.5. Backported Spark patch in Dataproc Serverless for Spark runtime 1.0 and 2.0: SPARK-40481: Ignore stage fetch failure caused by decommissioned executor.

Datastore - Support for the australia-southeast2 (Melbourne) region.

Terraform on Google Cloud - Published an update to the Terraform blueprints page.

Document AI - v1.3. We are launching a public preview version of the Purchase Order (PO) processor, pretrained-purchase-order-v1.1-2022-06-17, with the following new features: Support for uptraining to improve, add, and remove entities in the schema Support for uptraining to add support for unsupported languages Improvements to overall performance. v1beta3. The Document AI OCR Processor has the following new features: The OCR Processor now supports extracting embedded text from digital PDFs in public preview. Known issues with the digital PDF feature of the Document AI OCR Processor: On a small number of documents, the word ordering within lines of text as reported by native text extraction might be wrong.

Cloud Firestore - Support for the australia-southeast2 (Melbourne) region.

Cloud Functions - The option to update a Serverless VPC Access connector is now available in preview.

Google Kubernetes Engine - Dual-stack clusters in GKE are now generally available. A new vulnerability (CVE-2022-2602) has been discovered in the io_uring subsystem in the Linux kernel that can allow an attacker to potentially execute arbitrary code. You can now enable NCCL Fast Socket on your multi-GPU workloads. CVE-2022-37434, CVE-2022-40674, CVE-2022-1586, CVE-2022-1587 have been patched in the PD CSI driver in 1.22, 1.23, 1.24 for newly created clusters.

Cloud Logging - Cloud Logging now supports the following regions: US EU For more information, see Data regionality for Cloud Logging.

Pub/Sub Lite - Pub/Sub Lite now supports export subscriptions.

Retail Recommendations AI - Recommendations AI now provides the On-sale model.

Cloud Run - The option to update a Serverless VPC Access connector is now available in preview.

Security Command Center - The userName attribute was added to the Finding object of the Security Command Center API.

Cloud Spanner - The new Cloud Spanner Kafka connector publishes change streams records to Kafka for application integration and event triggering. You can now use the ALTER INDEX statement to add columns into an index or drop non-key columns.

Cloud SQL MySQL - Cloud SQL for MySQL now supports using the lower_case_table_names flag for MySQL 8.0.

Cloud Storage Transfer - Storage Transfer Service now offers Preview support for tracking progress of a Transfer Job using Cloud Monitoring, allowing you to monitor the number of objects and amount of data copied by Storage Transfer Service in near real-time.

Cloud TPU - Cloud TPU now supports TensorFlow patches: 2.8.4, 2.9.3, and 2.10.1.

Vertex AI - Vertex AI TensorFlow Profiler Vertex AI TensorFlow Profiler is generally available GA. Vertex AI Matching Engine Vertex AI Matching Engine now offers General Availability support for updating your indices using Streaming Update, which is real-time indexing for the Approximate Nearest Neighbor (ANN) service. Vertex AI Feature Store streaming ingestion is now generally available (GA). You can now override the default data retention limit of 4000 days for the online store and the offline store in Vertex AI Feature Store.

VMware Engine - VMware Engine nodes are now available in the following additional region: Milan, Italy, Europe (europe-west8).

Virtual Private Cloud - Preview: You can use geo-location objects in firewall policy rules to filter external IPv4 and external IPv6 traffic based on specific geographic locations or regions. Preview: You can use Threat Intelligence for firewall policy rules to secure your network by allowing or blocking traffic based on threat intelligence data. Preview: You can use address groups to combine multiple IP addresses and IP ranges into a single named logical unit. Preview: You can use fully qualified domain name (FQDN) objects in firewall policy rules to filter incoming or outgoing traffic from specific domain names.

If you have suggestion, feedback or link you want to share feel free to email me at zdenko@gcpweekly.com

Have a great week,

Zdenko

To make sure you keep getting these emails, please add zdenko@gcpweekly.com to your address book or whitelist us. Want out of the loop? Unsubscribe. Our postal address: Třebanická 183, Prague, Prague 14300

Older messages

GCP Newsletter #325

Monday, December 19, 2022

Welcome to issue #325 December 19th, 2022 News AlloyDB Data Analytics Infrastructure Official Blog Announcing the General Availability of AlloyDB for PostgreSQL - Migrate and modernize legacy databases

GCP Newsletter #324

Monday, December 12, 2022

Welcome to issue #324 December 12th, 2022 News Official Blog Public Sector Announcing Google Cloud support for Impact Level 5 (IL5) workloads - Google Cloud now has an IL5 provisional authorization,

GCP Newsletter #323

Monday, December 5, 2022

Welcome to issue #323 December 5th, 2022 News Analytics Hub Data Analytics Official Blog Secure data exchanges with Analytics Hub, now generally available - Efficiently and securely exchange valuable

GCP Newsletter #322

Monday, November 28, 2022

Welcome to issue #322 November 28th, 2022 It's unusual, but no real official news from last week so we'll jump straight into community articles. Articles, Tutorials Infrastructure, Networking,

GCP Newsletter #321

Monday, November 21, 2022

Welcome to issue #321 November 21st, 2022 News Cloud Storage Infrastructure Official Blog Simplify and automate cost optimization with Autoclass for Cloud Storage - Autoclass simplifies data lifecycle

You Might Also Like

🔎 How to Search Reddit Like a Pro — 9 Reasons to Always Use Windows With a VPN

Tuesday, November 12, 2024

Also: Tips for Setting Up a Mobile VR Office, and More! How-To Geek Logo November 12, 2024 Did You Know In the 2016 film Doctor Strange, the characters of both Doctor Strange and the villain Dormammu (

Web Scraping Tips, Python 3.13 Performance Boosts, Writing Interpreters & More

Tuesday, November 12, 2024

Introduction to Web Scraping With Python #655 – NOVEMBER 12, 2024 VIEW IN BROWSER The PyCoder's Weekly Logo Introduction to Web Scraping With Python In this video course, you'll learn all about

Daily Coding Problem: Problem #1606 [Easy]

Tuesday, November 12, 2024

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by PayPal. Given a binary tree, determine whether or not it is height-balanced. A height-

Charted | Breaking Down the U.S. Government's 2024 Fiscal Year 💰

Tuesday, November 12, 2024

Net interest payments cost the US government $882 billion in fiscal year 2024, the third-largest outlay in the final budget. View Online | Subscribe | Download Our App Presented by Hinrich Foundation

Spyglass Dispatch: AI's Independence Race • EU's Bad Meta Ads • AI Chip Shenanigans • Netflix Ads Religion

Tuesday, November 12, 2024

AI's Independence Race • EU's Bad Meta Ads • AI Chip Shenanigans • Netflix Ads Religion The Spyglass Dispatch is a free newsletter sent out daily on weekdays. Feel free to forward it on to

The Big T

Tuesday, November 12, 2024

Top Tech Content sent at Noon! How the world collects web data Read this email in your browser How are you, @newsletterest1? 🪐 What's happening in tech today, November 12, 2024? The HackerNoon

Deadline Extended: 2 Weeks Left to Compete for Over $7000 in the AI-chatbot Writing Contest🔥

Tuesday, November 12, 2024

Great news, newsletterest1 ! The submission deadline for the #ai-chatbot writing contest has been extended! You now have until November 21, 2024, to submit your unique AI chatbot ideas for a chance to

A very demure, very mindful issue

Tuesday, November 12, 2024

Plus a look at memory regions, Go's birthday, and we invent a brand new word. | #​531 — November 12, 2024 Unsub | Web Version Together with Frontend Masters logo Go Weekly Happy Birthday, Go! Go

Visual Capitalist is revealing all of its biggest secrets... 📊

Tuesday, November 12, 2024

You can get in on our newest project if you act now. View Online | Subscribe | Download Our App We're revealing our biggest secrets... The question we get asked the most is: "How does Visual

🔓🐍 Unlock Your Python Potential with Instructor-Led Courses

Tuesday, November 12, 2024

Hey there, If you've been looking for a way to go beyond on-demand tutorials and really master Python, we've got something special for you... For the first time, Real Python is launching an