Menu

Google Enhances GKE With Advanced Security, “Cluster Fleet” Management

Google Enhances GKE With Advanced Security, “Cluster Fleet” Management

The News: Google launched GKE Enterprise, a premium version of its Google Kubernetes Engine managed service, at Google Cloud Next ’23. You can read more details of the announcement on the Google Cloud blog.

Google Enhances GKE With Advanced Security, “Cluster Fleet” Management

Analyst Take: Kubernetes, an open-source container orchestration platform, has its roots deeply embedded in Google’s internal infrastructure. The origin story of Kubernetes dates to Google’s internal project called “Borg,” a large-scale cluster manager developed to handle Google’s global-scale billion user plus services such as Gmail and YouTube. Borg’s architectural principles, along with its operational experience, laid the foundation for Kubernetes.

In mid-2014, Google decided to bring these previously internally developed advancements to the broader community by open-sourcing Kubernetes. The initial release was developed by Joe Beda, Brendan Burns, and Craig McLuckie, who took key ideas from Borg, but Google Kubernetes Engine (GKE) is Google’s commercial version of Kubernetes, and forms the bedrock of Google container offerings. GKE Enterprise combines GKE, a service for running containers solely in the Google Cloud, and Google Anthos for running Kubernetes in hybrid and multi-clouds. The Enterprise version improves Kubernetes management through additional security, governance, service mesh management, a dashboard to see all workloads, and “cluster fleets.”

GKE Enterprise edition incorporates Google’s Anthos multi-cluster fleet management capabilities. That approach lets platform engineers group similar workloads into dedicated clusters, apply custom configurations and policy guardrails per fleet, isolate sensitive workloads, and delegate cluster management to other teams. GKE Enterprise’s managed security features include advanced workload vulnerability insights, governance and policy controls, and managed service mesh. Hybrid and multi-cloud support in GKE Enterprise allows customers to run container workloads anywhere GKE, in other public clouds, or on-premises with Google Distributed Cloud.

GKE Enterprise edition will be available in preview in early September, with launch partners Accenture, CDW, Deloitte, DoiT International, SADA, Searce, and 66degrees.

GKE Enterprise also tied into other Google Next launches. Users can run Cloud TPU workloads on GKE to take advantage of features such as autoscaling, workload orchestration, and support for 15,000 node clusters when developing AI models. Google enhanced Cloud TPU at the conference with version v5e, with up to 2x higher training performance and 2.5x higher inference performance per dollar for large language models (LLMs) and gen AI models compared to Cloud TPU v4.

When running workloads in GKE, customers can save commute cycles by scaling up and down according to demand because they only pay for TPU resources provisioned.

Other GKE announcements at Google Next included:

  • GKE now supports A3 VM with NVIDIA H100 GPU for training large models
  • Cloud Storage FUSE is in general availability on GKE for moving unstructured data workloads to GKE without changing how that data is accessed
  • The ability to run Duet AI and Cloud Run in GKE is available in preview

The Futurum Group’s research shows an overwhelming majority (84%) of customers want a container management system that is integrated, maintained, and supported by a commercial vendor. Also, the biggest challenges to Kubernetes adoption are lack of talent to manage the new technology and difficulty keeping people who do have that expertise.

Those trends work in Google’s favor because it offers container management as a commercial service integrated with other services. We see GKE Enterprise as an extension of Google’s rich Kubernetes and AI/ML capabilities. Google is already the industry leader in Kubernetes, and combines that value with a robust suite of AI/ML and data services to support rapid innovation. In this case, it has already impressively integrated GKE Enterprise with its other new AI services at launch.

Looking Ahead

The market for commercial container orchestration and management solutions is led by Red Hat with its OpenShift solution, with the likes of SUSE with Rancher Prime also figuring into the market equation, especially in Europe. As Kubernetes becomes the default for modern hybrid multi-cloud management and deployment, the competitive landscape for which vendor leads this vital control plane will be interesting to watch as public cloud deployments eventually outweigh on-premises deployments.

Customers are increasingly facing a choice with how they look to deploy Kubernetes. On one hand, public cloud providers are offering fully managed “enterprise-grade” offerings such as this newly-announced service from Google and the likes of EKS and ECS from AWS, whereas others partner with Red Hat or SUSE and take a platform-neutral approach. We believe that customers should carefully weigh the simplicity and one-stop shopping benefits of public cloud-provided K8S services against the neutrality of third-party offerings as they make what could be the most pivotal deployment choice in their hybrid cloud strategy.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other insights from The Futurum Group:

Previewing Google Cloud Next ‘23

Research Study: Unlocking the Gate to Digital Transformation

Open vs. Closed-Source: the State of Kubernetes Protection

Author Information

Steven engages with the world’s largest technology brands to explore new operating models and how they drive innovation and competitive edge.

Dave focuses on the rapidly evolving integrated infrastructure and cloud storage markets.

Related Insights
Harness Incident Agent Is DevOps Now The AI Engineers of Software Delivery
January 22, 2026

Harness Incident Agent: Is DevOps Now The AI Engineers of Software Delivery?

Mitch Ashley, VP & Practice Lead, Software Lifecycle Engineering at Futurum, analyzes Harness's introduction of the Human-Aware Change Agent and what it signals about AI agents emerging across software delivery,...
January 21, 2026

AI-Enabled Enterprise Workspace – Futurum Signal

The enterprise workspace is entering a new phase—one shaped less by device refresh cycles and more by intelligent integration. As AI-enabled PCs enter the mainstream, the real challenge for IT...
AWS European Sovereign Cloud Debuts with Independent EU Infrastructure
January 16, 2026

AWS European Sovereign Cloud Debuts with Independent EU Infrastructure

Nick Patience, AI Platforms Practice Lead at Futurum, shares his/her insights on AWS’s launch of its European Sovereign Cloud. It is an independently-run cloud in the EU aimed at meeting...
GitLab’s Salvo in the Agent Control Plane Race
January 16, 2026

GitLab’s Salvo in the Agent Control Plane Race

Mitch Ashley, VP and Practice Lead, Software Lifecycle Delivery at Futurum, analyzes how GitLab’s GA Duo Agent Platform positions the DevSecOps platform as the place where agent-driven delivery is controlled,...
Dynatrace Brings Feature Management Into the Observability Control Plane
January 15, 2026

Dynatrace Brings Feature Management Into the Observability Control Plane

Mitch Ashley, VP and Practice Lead for Software Lifecycle Engineering at Futurum, analyzes how Dynatrace’s move to native feature management inside observability enables agent-driven delivery, tighter release control, and runtime...
As CrowdStrike Buys Seraphic, Is Browser Security Destined to Be Just a Feature
January 15, 2026

As CrowdStrike Buys Seraphic, Is Browser Security Destined to Be Just a Feature?

Fernando Montenegro, VP at Futurum, analyzes CrowdStrike's acquisition of Seraphic Security, a strategic move to secure the browser "blind spot" and extend Falcon's visibility to unmanaged devices....

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.