GKE Gateway adds support for backend mutual TLS
Google Kubernetes Engine Gateway now supports backend mutual TLS (mTLS), allowing the load balancer to authenticate its identity to backend Pods using a client certificate. This enhancement improves security by enabling stricter authentication between the Gateway and backend services. The feature is available for specific GatewayClasses and configured via the standard Gateway API.
Features (1) ›
- Google Kubernetes Engine
GKE Gateway now supports backend mutual TLS (mTLS). In addition to backend authenticated TLS, backend mTLS allows the GKE Gateway load balancer to authenticate its identity to backend Pods by presenting a client certificate. GKE Gateway configures backend mTLS using the standard Gateway API spec.tls.backend.clientCertificateRef field. This feature is supported for the following GatewayClasses: gke-l7-global-external-managed gke-l7-regional-external-managed gke-l7-rilb For more information, see Configure backend mutual TLS (mTLS) for a Gateway .
https://docs.cloud.google.com/release-notes#July_07_2026
Related releases
- Bringing gVisor Sandboxes to Distributed Ray Clusters on Google Cloud Google Cloud Blog ·
- Assured Workloads enhances data residency controls and ITAR support Google Cloud release notes ·
- Cluster Toolkit v1.99.0 Enhances Slurm with Prometheus Telemetry and GKE TPU Examples Google Cloud release notes ·
- GKE Cluster Toolkit v1.100.0 Enhances Namespace Ops, Updates Slurm & Kueue Google Cloud release notes ·
- GKE Deprecates Non-Release Channel Clusters, Freezes Windows Server 2019 Image Updates Google Cloud release notes ·
- Google Kubernetes Engine Updates Versions and Deprecates Older Releases Google Cloud release notes ·