tag:google.com,2016:iap-release-notes Identity-Aware Proxy - Release notes Google Cloud Platform 2024-09-20T00:00:00-07:00 September 20, 2024 tag:google.com,2016:iap-release-notes#September_20_2024 2024-09-20T00:00:00-07:00 <![CDATA[

Feature

Preview: You can now use authorization policies to delegate authorization to Identity-Aware Proxy (IAP) and Identity and Access Management (IAM). For more information, see Use authorization policies to delegate authorization to IAP and IAM.

]]>
June 28, 2024 tag:google.com,2016:iap-release-notes#June_28_2024 2024-06-28T00:00:00-07:00 <![CDATA[

Changed

On February 14, 2024, the Cloud Audit Logging (CAL) type was inadvertently changed from DATA_ACCESS to ADMIN_ACTIVITY. This change causes a change in the log name and log bucket location for the UpdateIapSettings and ValidateIapAttributeExpression methods.

The CAL type has been changed back to DATA_ACCESS.

]]>
May 16, 2024 tag:google.com,2016:iap-release-notes#May_16_2024 2024-05-16T00:00:00-07:00 <![CDATA[

Feature

Generally Available: Service accounts can now use JSON Web Tokens (JWTs) to programmatically access resources protected by Identity-Aware Proxy (IAP). This provides a streamlined authentication process for workloads accessing IAP-protected applications and services. For more information, see Programmatic authentication.

]]>
May 06, 2024 tag:google.com,2016:iap-release-notes#May_06_2024 2024-05-06T00:00:00-07:00 <![CDATA[

Feature

Identity-Aware Proxy (IAP) now supports Workforce Identity Federation for application access. You can now use your extended workforce identities to access IAP-protected applications without having to sync your identities into Cloud Identity. For more information, see Configure IAP with Workforce Identity Federation.

]]>
April 23, 2024 tag:google.com,2016:iap-release-notes#April_23_2024 2024-04-23T00:00:00-07:00 <![CDATA[

Feature

WebSocket support for managing Compute Engine resource sessions is now available. For more information, see Managing IAP sessions .

]]>
February 01, 2024 tag:google.com,2016:iap-release-notes#February_01_2024 2024-02-01T00:00:00-08:00 <![CDATA[

Changed

Effective January 12, 2024, a BeyondCorp Enterprise license is no longer required to deploy internal applications with an internal load balancer when securing those applications with Identity-Aware Proxy. This provides a consistent experience when using Identity-Aware Proxy with all load balancers.

]]>
January 16, 2024 tag:google.com,2016:iap-release-notes#January_16_2024 2024-01-16T00:00:00-08:00 <![CDATA[

Changed

A BeyondCorp Enterprise license is no longer required when configuring Identity-Aware Proxy with an internal load balancer.

This note is incomplete; see entry for February 1, 2024.

]]>
August 17, 2023 tag:google.com,2016:iap-release-notes#August_17_2023 2023-08-17T00:00:00-07:00 <![CDATA[

Feature

Authenticating users with a Google-managed OAuth client and allowlisting OAuth clients for programmatic access are available in Preview.

]]>
April 07, 2023 tag:google.com,2016:iap-release-notes#April_07_2023 2023-04-07T00:00:00-07:00 <![CDATA[

Feature

Support for Identity-aware Proxy (IAP) with Cloud Run to use identity and context to guard access to your applications is now at general availability (GA).

]]>
September 16, 2021 tag:google.com,2016:iap-release-notes#September_16_2021 2021-09-16T00:00:00-07:00 <![CDATA[

Security

Security bulletin c2agxr12ne

Certain Google Cloud load balancers routing to an Identity-Aware Proxy enabled Backend Service could have been vulnerable to an untrusted party under limited conditions.

For details, see GCP-2021-020

]]>
May 29, 2020 tag:google.com,2016:iap-release-notes#May_29_2020 2020-05-29T00:00:00-07:00 <![CDATA[

Feature

The ability to authenticate users with external identities is now generally available.

]]>
February 12, 2020 tag:google.com,2016:iap-release-notes#February_12_2020 2020-02-12T00:00:00-08:00 <![CDATA[

Feature

API for OAuth clients now generally available

You can now programmatically create OAuth clients in IAP via REST or gcloud. See this topic for more information.

]]>
August 07, 2019 tag:google.com,2016:iap-release-notes#August_07_2019 2019-08-07T00:00:00-07:00 <![CDATA[

Feature

Cloud IAP TCP forwarding general availability release

Using Cloud IAP for TCP forwarding is now generally available. Cloud IAP for TCP forwarding lets you control who can access administrative services like SSH and RDP on your backends.

]]>
April 10, 2019 tag:google.com,2016:iap-release-notes#April_10_2019 2019-04-10T00:00:00-07:00 <![CDATA[

Feature

Cloud IAP with context-aware access general availability release

The ability to extend Cloud IAP access policies with access levels and the IAM Conditions Framework is now generally available.

]]>
February 26, 2019 tag:google.com,2016:iap-release-notes#February_26_2019 2019-02-26T00:00:00-08:00 <![CDATA[

Feature

Cloud IAP for on-premises apps general availability release

You can now manage access to HTTP-based apps outside of Google Cloud Platform. This includes apps on-premises in your enterprise's data centers and on other cloud providers.

]]>
February 14, 2019 tag:google.com,2016:iap-release-notes#February_14_2019 2019-02-14T00:00:00-08:00 <![CDATA[

Feature

Cloud IAP Per-Resource Policies general availability release

The ability to manage Cloud IAP policies for each individual resource in a Google Cloud Platform project is now generally available.

]]>
January 22, 2019 tag:google.com,2016:iap-release-notes#January_22_2019 2019-01-22T00:00:00-08:00 <![CDATA[

Feature

Cloud IAP TCP forwarding beta release

You can now use Cloud IAP for TCP forwarding, allowing you to control who can access administrative services like SSH and RDP on your backends.

]]>
October 04, 2018 tag:google.com,2016:iap-release-notes#October_04_2018 2018-10-04T00:00:00-07:00 <![CDATA[

Feature

Cloud IAP with context-aware access beta release

Cloud IAP access policies for Cloud IAP-secured applications, services, and versions have been extended to use access levels and the IAM Conditions Framework. Access levels allow access restrictions to resources based on IP address and end-user device attributes. IAM conditions allow access restrictions based on URL hosts, paths, date, and time.

]]>
August 16, 2018 tag:google.com,2016:iap-release-notes#August_16_2018 2018-08-16T00:00:00-07:00 <![CDATA[

Feature

Cloud IAP Per-Resource Policies beta release

Cloud IAP policies can now be managed for each individual resource in a GCP project.

]]>
August 31, 2017 tag:google.com,2016:iap-release-notes#August_31_2017 2017-08-31T00:00:00-07:00 <![CDATA[

Feature

Welcome to the Cloud IAP general release for App Engine standard environment, Compute Engine, and GKE!

Issue

Cloud IAP for App Engine flexible environment is still in beta. This feature is not covered by any SLA or deprecation policy and may be subject to backward-incompatible changes for App Engine flexible environment.

Changed

Java code samples were updated with security enhancements on August 15, 2017. If you're using the Java signed headers code sample, please update your application per the current samples.

Changed

When you use the programmatic authentication feature, the aud claim in the JWT must now be the Cloud IAP client ID. Previously, it could also be the application URL. For applications that used programmatic authentication recently, we placed this feature on our whitelist. We will remove the functionality on November 15, 2017. For details and updated code samples, refer to programmatic authentication.

Changed

Due to internal security enhancements, App Engine standard environment apps no longer require login: required in app.yaml (or security-constraint for Java).

Feature

Forseti Security is now available and strongly encouraged for Compute Engine apps. If you have any questions or require assistance, please post to [email protected].

Feature

Cloud IAP now supports Cloud Audit Logging. Learn about enabling Cloud Audit Logging.

Feature

Cloud IAP now supports desktop and command-line applications. Learn about authenticating from a desktop app.

Feature

AJAX requests with missing or expired credentials will now get an HTTP 401 response instead of being served a Google login page.

]]>
August 07, 2017 tag:google.com,2016:iap-release-notes#August_07_2017 2017-08-07T00:00:00-07:00 <![CDATA[

Fixed

Cloud IAP can once again be enabled for App Engine flexible environment apps.

]]>
July 20, 2017 tag:google.com,2016:iap-release-notes#July_20_2017 2017-07-20T00:00:00-07:00 <![CDATA[

Feature

Cloud IAP now supports special URLs to help you enhance and personalize your app.

]]>
July 14, 2017 tag:google.com,2016:iap-release-notes#July_14_2017 2017-07-14T00:00:00-07:00 <![CDATA[

Changed

Cloud IAP now uses the following values when you secure your app with signed headers:

  • The JWT is now in the HTTP request header x-goog-iap-jwt-assertion instead of x-goog-authenticated-user-jwt.
  • When you verify the ID token payload, the aud value should now be a string with client ID details instead of a URL.
]]>
July 11, 2017 tag:google.com,2016:iap-release-notes#July_11_2017 2017-07-11T00:00:00-07:00 <![CDATA[

Feature

Added best practices for caching.

]]>
June 19, 2017 tag:google.com,2016:iap-release-notes#June_19_2017 2017-06-19T00:00:00-07:00 <![CDATA[

Feature

Cloud Audit Logging is now available for Cloud IAP-secured resources. Read about how to Enable Cloud Audit Logging.

Changed

The Cloud IAP 403 "failed access" page now includes product and email details from the OAuth consent screen. As with the login page, these details are publicly visible to anyone who accesses your URL. You can change the information that displays on the OAuth consent screen.

]]>
June 07, 2017 tag:google.com,2016:iap-release-notes#June_07_2017 2017-06-07T00:00:00-07:00 <![CDATA[

Feature

Added information about Authenticating from a desktop app for Cloud IAP-secured resources.

]]>
April 17, 2017 tag:google.com,2016:iap-release-notes#April_17_2017 2017-04-17T00:00:00-07:00 <![CDATA[

Changed

When you use Cloud IAP with Compute Engine, GKE, or the App Engine flexible environment, you must also use signed headers to secure your app.

Issue

Cloud IAP can't currently be enabled for App Engine flexible environment apps.

]]>
March 09, 2017 tag:google.com,2016:iap-release-notes#March_09_2017 2017-03-09T00:00:00-08:00 <![CDATA[

Issue

Cloud IAP has a static 403 "failed access" page. In a future release, admins will be able to customize the failure message text.

]]>