GKE Gateway adds support for backend mutual TLS
Google Kubernetes Engine Gateway now supports backend mutual TLS (mTLS), allowing the load balancer to authenticate its identity to backend Pods using a client certificate. This enhancement improves security by enabling stricter authentication between the Gateway and backend services. The feature is available for specific GatewayClasses and configured via the standard Gateway API.
Features (1) ›
- Google Kubernetes Engine
GKE Gateway now supports backend mutual TLS (mTLS). In addition to backend authenticated TLS, backend mTLS allows the GKE Gateway load balancer to authenticate its identity to backend Pods by presenting a client certificate. GKE Gateway configures backend mTLS using the standard Gateway API spec.tls.backend.clientCertificateRef field. This feature is supported for the following GatewayClasses: gke-l7-global-external-managed gke-l7-regional-external-managed gke-l7-rilb For more information, see Configure backend mutual TLS (mTLS) for a Gateway .
https://docs.cloud.google.com/release-notes#July_07_2026
Related releases
- Config Connector 1.154.1 Adds New Alpha Resources and Field Support Google Cloud release notes ·
- Google Cloud AI Infrastructure and Orchestration Updates - July 2026 Google Cloud Blog ·
- Google Kubernetes Engine: New versions and deprecations Google Cloud release notes ·
- Managed Service for Apache Spark drops default Conda channels Google Cloud release notes ·
- GKE Optimizations Reduce AI Agent Compute Costs Up To 75% Google Cloud Blog ·
- Cloud SDK 578.0.0: Database Migration default change, AlloyDB backup DR GA, BigQuery improvements Google Cloud release notes ·