GCP

GKE Agent Substrate (Evaluation) & Cloud Run Instances (Preview) — Persistent Singletons for Google Cloud Agents

Agent Substrate is in evaluation and Cloud Run Instances are in Preview, formalizing long‑lived addressable serverless agents and new ops/security tradeoffs.

October 8, 2026·3 min read·AI researched · AI written · AI reviewed

Google Cloud just made a pragmatic, overdue concession: some serverless workloads need to be long‑lived and addressable. Two releases in the same window — GKE Agent Substrate opened for evaluation/non‑prod, and Cloud Run instances moved into Preview — formalize persistent singletons as a supported execution pattern rather than an awkward hack.

The concrete bits you need to know now: Agent Substrate is available for evaluation and non‑production use; production access currently requires enrollment in Google's GA/allowlist program. Cloud Run Instances (Preview) expose individually addressable, longer‑lived runtimes so you can run singletons without forcing a scale‑to‑zero model. This Preview signals a supported capability rather than a pricing change; check the Cloud Run and GKE docs for current limits and billing details.

Why this matters

For the last few years platform teams shoehorned agents and other stateful, always‑on tasks into tools never designed for them: tiny VMs, DaemonSets, or ephemeral serverless functions with external heartbeats. That's inefficient and operationally leaky. Cloud Run Instances and GKE Agent Substrate acknowledge a middle ground — serverless convenience with process longevity.

Two practical follow‑ups follow immediately:

  • Cost behaviour changes: continuous runtimes remove scale‑to‑zero savings. A single Cloud Run instance running 24/7 for a month becomes a predictable line item. Plan budgets accordingly and track per‑instance utilization.
  • Operational model changes: these are long‑lived processes, not request handlers. Treat them like services: health probes, OOM and leak monitoring, structured restarts, secrets rotation, and upgrade rollouts.

Where to use each

Cloud Run Instances are a natural fit for agents that need an HTTP‑addressable endpoint or a managed serverless runtime with low ops overhead, e.g., a single‑tenant AI agent, an interactive websocket bot, or a per‑customer worker that needs persistent local state for minutes to days. GKE Agent Substrate looks targeted at workloads that need deeper host integration, node isolation, or kernel visibility — think security agents, device connectors, or intrusion detection runtimes that demand node‑level APIs.

The operational wall you didn't expect

This adds an attack surface that teams routinely underestimate. Long‑lived runtimes mean persisted credentials, in‑memory caches, and longer dwell times for attackers. Automatic restarts are convenient, but they can hide flapping failures or mask slow memory leaks.

Treat these instances as stateful processes:

  • Enforce short‑lived credentials and automatic rotation; assume an instance compromise is a long‑lived exposure until rotated.
  • Add process‑level telemetry: heap/GC metrics, thread counts, and native memory profiling for languages that leak outside managed heaps.
  • Use readiness/health endpoints that reflect both liveness and functional readiness (not just HTTP 200).

The allowlist GA for Agent Substrate also tells you something: Google knows this isn't trivial. Agent runtimes touch host resources and require tighter vendor support. Don't roll these into production at scale until your incident playbooks and RBAC are exercised.

A final, blunt take

This is the right move. Cloud providers needed to stop pretending everything can be scale‑to‑zero. The ecosystem has been building agent frameworks and persistent runtimes anyway; making them first‑class lets vendors provide lifecycle, billing, and security primitives instead of teams inventing brittle workarounds. That said, teams that treat Cloud Run Instances as just another function will get burned — uptime costs, memory leaks, and credential sprawl are real.

If you run agents today, inventory them this week: which can live in a managed singleton, which need node privileges, and which should stay in GKE. If you want a concise intro to these changes and how they landed in the GKE 1.35 release, see the official release notes and coverage in the product docs.

Prediction: within 12 months tooling will standardize for these patterns — cost dashboards with per‑instance chargebacks, agent lifecycle managers, and hardened secrets rotation built into the runtimes. If your team hasn't budgeted for persistent serverless yet, it will become a line item on next year's cloud bill.

Sources

gkecloud-rungoogle-cloudserverless-agents
← All articles
GCP

GKE 1.35.6: Agent Substrate evaluation, Agent Platform compute SKU, and Cloud Run Instances (Preview)

Agent Substrate on GKE is available for evaluation with GA gated by an allowlist. Agent Platform compute is billable; Cloud Run Instances enter Preview.

Oct 7, 2026·3mgkecloud-run
GCP

GKE 1.36: Agent Substrate on GKE and Cloud Run Instances for Persistent Agents

GKE Rapid-channel defaults to 1.36; Agent Substrate is available for evaluation with limited GA access. Cloud Run Instances (Preview) enable always-on singletons.

Oct 5, 2026·3mgkecloud-run-instances
GCP

Cloud Run instances: Dedicated singleton runtimes for up to seven days

Cloud Run instances preview offers dedicated singleton runtimes with up to seven days continuous execution; rethink isolation, restart semantics, and cost.

Oct 4, 2026·3mcloud-run-instancesgke-agent-sandbox