proomt

Search

Search posts, papers, and topics

All posts

Google Cloud BlogSenzeni Mpofu2 min readintermediate

Introducing new session management tools with native, granular controls

Summary

Google Cloud adds programmable session controls that can be managed via Terraform, gcloud CLI, and REST APIs, with policies scoped to Google Groups and individual applications, moving away from org‑unit defaults.

  • Session controls can now be defined as code using Terraform, gcloud, or REST APIs, enabling CI/CD enforcement.
  • Policies target Google Groups instead of OUs, allowing distinct session lengths per user cohort.
  • Admins can apply session limits to specific apps (Console, gcloud, OAuth apps) to avoid blanket disruptions.
  • A Cloud Console UI preview lets admins manage session policies alongside other Access Context Manager bindings.

Security teams and platform engineers who need fine‑grained reauthentication policies will benefit from automated, context‑aware session management.

5/10

Related reading

  1. Five CI Tools, One Control Plane: Finally Answer “What’s Going On?”

    CloudBees Unify is a control‑plane overlay that connects existing CI tools (GitHub Actions, Jenkins, GitLab, Bitbucket, CloudBees CI) to provide a single dashboard, centralized policy enforcement, audit trails, and artifact lineage without requiring migration of pipelines. The post outlines a 30‑60‑90‑day rollout plan and the expected benefits for platform teams.

    Codeshipcloudbees.com3 min
  2. Accelerating the borderless Lakehouse: Announcing preview of cross-cloud caching

    Google Cloud previewed cross‑cloud caching for its Borderless Lakehouse. The feature caches sub‑file Parquet blocks in Google Cloud, encrypts them with GMEK, isolates cache per tenant/region, and validates freshness via metadata checks. In tests it can reduce cross‑cloud data transfer to <5% of the original size, lowering query latency and cost for Iceberg tables stored in other clouds. BigQuery…

    Google Cloud Bloggoogle.com3 minrelease
  3. Introducing Filestore agent volumes: fully managed storage for agent workspaces

    Google Cloud adds Filestore agent volumes, a fully‑managed, elastic file‑system that automatically provisions isolated POSIX workspaces for GKE‑based AI agent sandboxes. Volumes attach in milliseconds, support RWX with file‑level locking, and charge only for used capacity with automatic tiering, aiming to cut cold‑start latency and storage waste for large‑scale agent fleets.

    Google Cloud Bloggoogle.com4 min
  4. Why Every Enterprise Needs a DevSecOps Control Plane

    The article argues that enterprises need a DevSecOps control plane to unify fragmented CI/CD tools, enforce security policies, and provide AI‑aware context. CloudBees Unify is presented as a solution that claims large reductions in release prep time and outages without requiring tool migration.

    Codeshipcloudbees.com6 min