Unlocking High-Performance AI/ML in Kubernetes with DRANet and RDMA

DraNet Enters Beta! High-Performance Networking in Kubernetes

by Antonio Ojea & Federico Bongiovanni, Kubernetes/GKE

We are excited to announce that DraNet has officially entered a beta state! This marks a major leap forward in our mission to streamline and enhance high-performance networking for AI and HPC workloads within Kubernetes. As we progress towards a stable General Availability (GA) release, we are eager to gather your feedback on the current state of the project.

Why DraNet?

DraNet was born from the lessons we learned at Google, observing the challenges end-users faced when running AI and HPC workloads on Kubernetes. The existing networking solutions, often repurposed from traditional networking or bespoke and complex, fell short of providing a good user experience and efficient operational models.
For instance, managing RDMA (Remote Direct Memory Access) interfaces often involved a complex combination of CNI chaining and device plugins. This not only created an unnecessary operational overhead for administrators but also led to coordination issues between different components that needed to work in harmony impacting resilience and scalability.
Another significant pain point we identified was the need for fine-grained interface tuning. AI workloads, for example, are extremely sensitive to latency. The presence of some eBPF programs on network interfaces, or the need to configure specific NIC parameters, could severely impact performance latency and/or throughput. Users were often forced to create custom init containers just to apply these settings, adding another layer of complexity.

Introducing DraNet: A Native and Declarative Solution

DraNet is a native integration with Kubernetes that uses the core Dynamic Resource Allocation (DRA) API to address these challenges by treating high-performance network interfaces as first-class citizens in Kubernetes. Here's how:

  • Simplified RDMA Management: DraNet manages RDMA interfaces natively, handling the different requirements to offer a unified and seamless user experience. No more need for coordinating different components.
  • Declarative Interface Tuning: With DraNet, you can declaratively set interface properties. Need to disable eBPF programs to reduce packet processing overhead or set specific NIC parameters? You can now do this directly in your Kubernetes manifests, eliminating the need for custom scripts or init containers.
  • Standalone and Secure: DraNet is designed as a standalone binary, allowing it to run in a distroless container. This significantly reduces the attack surface and the frequency of security-related updates for the container image. By interacting directly with the kernel via stable APIs like netlink, it avoids dependencies on third-party projects, improving both resilience and performance.
  • Lightweight and Fast: The DraNet container image, with a compressed size of less than 50MB, has a direct impact on node startup times, allowing for faster deployment and scaling of your workloads.

Beta Release and the Road to GA

DraNet is now in a beta state, signifying that it is ready for broader community testing and feedback. This move to beta is aligned with the maturation of the Kubernetes Dynamic Resource Allocation (DRA) KEP (KEP-4381), a foundational technology for DraNet. We are continuing our active development as we work towards a future General Availability release.

We Welcome Your Feedback and Contributions!

DraNet is an open-source project, and we believe that community involvement is key to its success. As we work towards our GA release, we welcome your feedback, whether it's on the design, user experience, or performance.
You can contribute in many ways:

  • Code contributions: We have a fast-paced development cycle and welcome new contributors. Check out our contributing guidelines to get started.
  • Documentation: Help us improve our documentation to make it easier for new users to get started with DraNet.
  • Share your opinion: Your feedback is invaluable. Let us know how you are using DraNet and what we can do to make it better.

To learn more about DraNet and get started, please visit https://dranet.dev/. We look forward to building the future of high-performance networking in Kubernetes with you!

Chrome for Android Update

  Hi, everyone! We've just released Chrome 138 (138.0.7204.157) for Android. It'll become available on Google Play over the next few days. 

This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by filing a bug.


Android releases contain the same security fixes as their corresponding Desktop (Windows & Mac: 138.0.7204.157/158, Linux: 138.0.7204.157) unless otherwise noted.


Krishna Govind
Google Chrome

Stable Channel Update for Desktop

The Stable channel has been updated to 138.0.7204.157/.158 for Windows, Mac and 138.0.7204.157 for Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log.

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 6 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.


[$7000][425583995] High CVE-2025-7656: Integer overflow in V8. Reported by Shaheen Fazim on 2025-06-17

[NA][427162086] High CVE-2025-6558: Incorrect validation of untrusted input in ANGLE and GPU. Reported by Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group on 2025-06-23

[TBD][427681143] High CVE-2025-7657: Use after free in WebRTC. Reported by jakebiles on 2025-06-25



Google is aware that an exploit for CVE-2025-6558 exists in the wild.



We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

As usual, our ongoing internal security work was responsible for a wide range of fixes:

[431819349] Various fixes from internal audits, fuzzing and other initiatives


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista
Google Chrome

Link your Google Calendar booking pages when composing emails in Gmail

What’s changing 

To make sharing your availability even easier, we’re adding the ability to share your Google Calendar appointment booking page directly in your email. By clicking the Calendar icon at the bottom of your email draft, you will see the list of existing booking pages and an option to create a booking page. Once a booking page is selected, it will be inserted into the email draft. 

Who’s impacted 

End users 

Why you’d use it 

With this update, you can manage scheduling all in one place, eliminating the need to open multiple tabs to figure out when you’re available and then reiterate that in an email. In addition to reducing the back-and-forth when negotiating or scheduling meeting times, this feature is especially useful when scheduling time with customers, partners or people outside your organization whose calendars are not visible to you. 

Getting started 

  • Admins: There is no admin control required for this feature. 
  • End users: 
    • To add your booking page to an email draft, select the Calendar Icon > click the correct booking page (or create a booking page) > see the booking page inserted into your email draft > hit Send. 
    • Visit the Help Center to learn about appointment schedules in Google Calendar.

Rollout pace 

Availability 

  • Appointment schedules are available to all Google Workspace customers, Workspace Individual Subscribers, and users with personal Google accounts at no additional charge. 
    • Select features within appointment scheduling are only available to those with paid subscriptions. Please refer to this Help Center article to learn more. 

Resources

New tools to help drive success for one-time products

Posted by Laura Nechita – Product Manager, Google Play and Rejane França – Group Product Manager, Google Play

Starting today, Google Play is revamping the way developers can manage one time products, providing greater flexibility and new ways to sell. Play has continually enhanced the ways developers can reach buyers by helping you to diversify the way you can sell products.

Starting in 2022, we created more flexibility for subscriptions and a new Console interface. And now, we are bringing the same flexibility to one-time products, aligning the taxonomy for our one-time products. Previously known as in-app products, one-time product purchases are a vital way for developers to monetize on Google Play. As this business model continues to evolve, we've heard from many of you that you need more flexibility and less complexity in how you offer these digital products.

To address these needs, we're launching new capabilities and a new way of thinking about your products that can help you grow your business. At its core, we've separated what the product is from how you sell it. For each one-time product, you can now configure multiple purchase options and offers. This allows you to sell the same product in multiple ways, reducing operational costs by removing the need to create and manage an ever-increasing number of catalog items.

You might have already noticed some changes as we introduce this new model, which provides a more structured way to define and manage your one-time product offerings.

Introducing the new model

flow chart showing the new model hierarchy with one time product at the top, purchase options in the middle, and offers at the bottom

We're introducing a new three-level hierarchy for defining and managing one-time products. This new structure builds upon concepts already familiar from our subscription model and aligns the taxonomy for all of your in-app product offerings on Play.

    • One-time product: This object defines what the user is buying. Think of it as the core item in your catalog, such as a "Diamond sword", “Coins” or “No ads”.
    • Purchase option: This defines how the entitlement is granted to the user, its price, and where the product will be available. A single one-time product can have multiple purchase options representing different ways to acquire it, such as buying it or renting it for a set period of time. Purchase options now have two distinct types: buy and rent.
    • Offer: Offers further modify a purchase option and can be used to model discounts or pre-orders. A single purchase option can have multiple offers associated with it.

This allows for a more organized and efficient way to manage your catalog. For instance, you can have one "Diamond sword" product and offer it with a "Buy" purchase option in the US for $10 and a "Rent" purchase option in the UK for £5. This new taxonomy will also allow Play to better understand what the catalogue means, helping developers to further amplify their impact in Play surfaces.

More flexibility to reach more users

The new model unlocks significant flexibility to help you reach a wider audience and cater to different user preferences.

    • Sell in multiple ways: Once you've migrated to PBL 8, you can set up different ways of selling the same product. This reduces the complexity of managing numerous individual products for slightly different scenarios.
    • Introducing rentals: We're introducing the ability to configure items that are sold as rentals. Users have access to the item for a set duration of time. You can define the rental period, which is the amount of time a user has the entitlement after completing the purchase, and an optional expiration period, which is the time after starting consumption before the entitlement is revoked.
    • Pre-order capabilities: You can now set up one-time products to be bought before their release through pre-order offers. You can configure the start date, end date, and the release date for these offers, and even include a discount. Users who pre-order agree to pay on the release date unless they cancel beforehand.
    • No default price: we will remove the concept of default price for a product. Now you can set and manage the prices in bulk or individually for each region.
    • Regional pricing and availability: Price changes can now be applied to purchase options and offers, allowing you to set different prices in different regions. Furthermore, you can also configure the regional availability for both purchase options and offers. This functionality is available for paid apps in addition to one-time products.
    • Offers for promotions: Leverage offers to create various promotions, such as discounts on your base purchase price or special conditions for early access through pre-orders.

To use these new features you first need to upgrade to PBL 8.0. Then, you'll need to utilize the new monetization.onetimeproducts service of the Play Developer API or use the Play Developer Console. You'll also need to integrate with the queryProductDetailsAsync API to take advantage of these new capabilities. And while querySkuDetailsAsync and inappproducts service are not supported with the new model, they will continue to be supported as long as PBL 7 is supported.

Important considerations

    • With this change, we will offer a backwards compatible way to port your existing SKUs into this new model. The migration will happen differently depending on how you decide to interact with your catalogue the first time you change the metadata for one or more products.
    • New products created through Play Console UI are normalized. And products created or managed with the existing inappproducts service won't support these new features. To access them, you'll need to convert existing ones in the Play Developer Console UI. Once converted, a product can only be managed through the new Play Developer API or Play Developer Console. Products created through the new monetization.onetimeproducts service or through the Play Developer Console are already converted.
    • Buy purchase options marked as ‘Backwards compatible’ will be returned as response for calls through querySkuDetailsAsync API. At launch, all existing products have a backwards compatible purchase option.
    • At the time of this post, the pre-orders capability is available through the Early Access Program (EAP) only. If you are interested, please sign-up.
    • One-time products will be reflected in the earnings reports at launch (Base plan ID and Offer ID columns will be populated for newly configured one-time products). To minimise the potential for breaking changes, we will be updating these column names in the earnings reports later this year.

We encourage you to explore the new Play Developer API and the updated Play Console interface to see how this enhanced flexibility can help you better manage your catalog and grow your business.

We're excited to see how you leverage these new tools to connect with your users in innovative ways.



Google Play logo