GKE: Workload Identity timeouts, Gateway TLS auth
Workloads using Workload Identity in GKE 1.35+ may encounter transient timeouts connecting to the metadata server after node startup. A new feature adds backend authenticated TLS support for Gateway-originated connections to Pods and InferencePools in specific GatewayClasses. Users experiencing connection issues should consult the provided documentation for recommendations and workarounds.
Features (1) ›
- Google Kubernetes Engine
GKE Gateway now supports backend authenticated TLS for Gateway-originated connections to Pods or InferencePools for the following GatewayClasses: gke-l7-global-external-managed gke-l7-regional-external-managed gke-l7-rilb
Known issues (1) ›
- Google Kubernetes Engine
In GKE version 1.35 and later, workloads that use Workload Identity to authenticate to Google Cloud APIs might experience transient connectivity timeouts or refused connections to the GKE metadata server immediately following node startup. For recommendations and workarounds, see Timeout errors at Pod startup .
https://docs.cloud.google.com/release-notes#May_29_2026
Related releases
- Google Cloud Recognized as a Leader in Forrester Wave™: Public Cloud Platforms Q3 2026 Google Cloud Blog ·
- GKE introduces Agent Substrate to scale agentic workloads efficiently Google Cloud release notes ·
- Cluster Toolkit v1.102.0 Enhances GKE with MTC, Flex Volumes, and HPC Capabilities Google Cloud release notes ·
- Config Connector 1.156.0 Adds Alpha Resources for AI, Security, and Storage Google Cloud release notes ·
- GKE Updates Available Versions, Default Builds, and Deprecates Older Releases Google Cloud release notes ·
- GKE 1.37 Now Available, Deprecates Identity Service for GKE Google Cloud release notes ·