GKE Gateway adds identity-based access control with GCPAuthzPolicy & GCPAuthzExtension
Google Kubernetes Engine (GKE) Gateway now offers GCPAuthzPolicy and GCPAuthzExtension resources in Preview for versions 1.36 and later. These resources enable identity-based access control and zero-trust authorization on incoming traffic directly at the Gateway layer. This capability is supported on the `gke-l7-global-external-managed`, `gke-l7-regional-external-managed`, and `gke-l7-rilb` GatewayClasses.
Features (1) ›
- Google Kubernetes Engine
In GKE version 1.36 and later, GCPAuthzPolicy and GCPAuthzExtension resources for GKE Gateway are now available in Preview. You can use these resources to enforce identity-based access control and zero-trust authorization on incoming traffic at the Gateway layer. These capabilities are supported on the following GatewayClasses: gke-l7-global-external-managed gke-l7-regional-external-managed gke-l7-rilb For more information, see Configure the GCPAuthzExtension resource .
https://docs.cloud.google.com/release-notes#August_26_2026
Related releases
- Google details dynamic capacity management strategies for AI infrastructure Google Cloud Blog ·
- Google Distributed Cloud for Bare Metal Version 1.36.0-gke.532 Now Available Google Cloud release notes ·
- Google Distributed Cloud (software only) for VMware 1.36.0-gke.532 Released with Kubernetes 1.36 Google Cloud release notes ·
- FinOps for AI Agents: Flexible Billing and Cost Controls for Gemini Enterprise Google Cloud Blog ·
- GCP outlines best practices for dynamic capacity management in the AI era Google Cloud Blog ·
- GKE Resolves GPUDirect-TCPX Incompatibility for A3-highGPU Nodes Google Cloud release notes ·