> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-compute-release-information/features-introduced-in-compute-june-2023.md).

# Features Introduced in June 2023

Learn about the new Compute capabilities on Prisma® Cloud Enterprise Edition (SaaS) in June 2023.

The host, container, and serverless capabilities on the **Compute** tab are being upgraded starting on June 25, 2023. When upgraded, the version will be 30.02.123.

* [New Features in Prisma Cloud Compute](#new-features-prisma-cloud-compute)
* [API Changes](#api-changes)
* [Breaking Changes in API](#breaking-api-changes)
* [Deprecation Notice](#deprecation-notice)
* See also [Known Issues](/release-notes/prisma-cloud-known-issues/known-fixed-issues.md)

## New Features in Prisma Cloud Compute

| Feature                                                                                                                                                                                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **CVE Coverage Update**                                                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
|                                                                                                                                                                                             | <p>As part of the 30.00 release, Prisma Cloud has rolled out updates to its vulnerability data for Common Vulnerabilities and Exposures (CVEs) in the Intelligence Stream. The new additions are as follows:</p><ul><li>Fixed <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2253">CVE-2023-2253</a> (Severity: high) - Package: <code>github.com/docker/distribution</code>\* Upgrade to at least the <code>2.8.2-beta.1</code> version of the package if you are running <code>v2.8.x</code> release. If you use the code from the main branch, update at least to the commit after <a href="https://github.com/distribution/distribution/commit/f55a6552b006a381d9167e328808565dd2bf77dc">f55a6552b006a381d9167e328808565dd2bf77dc</a>.</li></ul>                                                                                                                                                                                    |
| **Enhancements**                                                                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Container Runtime Types in Defender Deployment Workflow**                                                                                                                                 | <p>The Defender deployment workflows now support <code>Docker</code>, <code>CRI-O</code>, and <code>Containerd</code> container runtime types.</p><p>When installing a Defender using <code>twistcli</code>, pass the <code>--container-runtime</code> flag with the selecttion for the runtime that you use - <code>docker</code>, <code>cri-o</code>, or <code>containerd</code>.</p><p><img src="/files/CfZ3OXPd3o2HL3ykoEEe" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Support custom compliance checks**                                                                                                                                                        | Added support for [custom compliance checks](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/compliance/custom_compliance_checks) on clusters running `containerd` runtime.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Added Support for Managed Identities in Azure**                                                                                                                                           | Added support for Azure Managed Identities to authenticate any Azure resources that support AD authentication without adding keys in Prisma Console. To use this [authentication method](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/agentless-scanning/onboard-accounts/onboard-azure), add an Azure role with required permissions to scan the resources under **Manage > Cloud accounts**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Support for New Operating Systems**                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Windows Server 2016**                                                                                                                                                                     | Reinstating the support for Defenders on Windows 2016. For details on the extended support from Microsoft, see the [Microsoft documentation](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2016).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Added new NAT gateway IP addresses**                                                                                                                                                      | <p>Prisma Cloud is adding new NAT IP addresses for the Compute SaaS Console Region in GCP. The egress IPs for connections from The Compute SaaS Console to the internet in us-east 1 (South Carolina) are: <code>34.139.64.150</code> and <code>34.139.249.192</code>.</p><p>Make sure to add these IP addresses to your allow list. These IP addresses will be added to the <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/get-started-with-prisma-cloud/enable-access-prisma-cloud-console#id7cb1c15c-a2fa-4072-b074-063158eeec08_idcb6d3cd4-d1bf-450a-b0ec-41c23a4d4280">documentation</a>.</p>                                                                                                                                                                                                                                                                                                       |
| **New Features in Agentless Security**                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Encrypted volumes support in GCP with hub mode**                                                                                                                                          | This feature adds the capability to scan encrypted volumes in GCP with agentless scanning when using hub mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **New Features in Host Security**                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Change in the format of runtime events information used in** [**notification webhooks**](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/alerts/webhook) | <p>Replaced the <code>aggregated</code> and <code>rest</code> macros with the following macros:</p><ul><li><code>aggregatedAlerts</code>: Returns the aggregated audit events in <code>JSON</code> format. It represents the same data as the old <code>aggregated</code> macro but in <code>JSON</code> format instead of text.</li><li><code>dropped</code>: Returns the number of alerts that were dropped after the aggregation buffer has reached its limit.</li></ul><p>This change fixes an issue where some of the aggregated alerts were missing fields like <code>ContainerID</code>, <code>Namespace</code>, and <code>User</code>.</p><p>The <code>aggregated</code> and <code>rest</code> macros are still available but are being deprecated after the two upcoming releases following our deprecation notice policy. For existing settings of alert providers, you must edit the alert structure and use the new macros.</p> |

## API Changes

| CHANGE                                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                |
| ----------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Add Backward Compatibility to api/v1/cloud/discovery/entities** | The **api/vVERSION/cloud/discovery/entities** API endpoint is now available as a supported and backward-compatible route to view the cloud discovered entities.                                                                                                                                                            |
| **Monitor the status of an OnDemand and Regular registry scan**   | The new API endpoint **api/vVERSION/registry/progress** is available to view the progress of onDemand and regular ongoing registry scans. Set the request parameter **onDemand** to true to view progress of an ongoing on-demand scan. By default, **onDemand** is set to false and shows the progress of a regular scan. |

## Breaking Changes in API

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>CHANGE</td><td>DESCRIPTION</td></tr><tr><td><strong>Defender APIs modified to support the containerd runtime</strong></td><td><p>The following APIs have been enhanced to include support for the containerd runtime in addition to the existing Docker and CRI-O runtimes:</p><ul><li>POST, <code>/api/vVERSION/defenders/daemonset.yaml</code></li><li>POST, <code>/api/vVERSION/defenders/helm/twistlock-defender-helm.tar.gz</code></li></ul><p>The <code>cri</code> boolean parameter (in the <code>common.DaemonSetOptions</code> schema) in the above endpoints has been replaced by the <code>common.ContainerRuntime</code> schema in the 30.02 release, as shown below:</p><p><strong>Old (30.01 and earlier releases)</strong></p><p>Example request schema showing <strong>cri</strong> set to a boolean value <strong>true</strong> for Docker and CRI-O:</p><pre><code>{
    "consoleAddr":"171.23.0.1",
    "namespace":"twistlock",
    "orchestration":"kubernetes",
    "selinux":false,
    "cri":true,
    "privileged":false,
    "serviceAccounts":true,
    "istio":false,
    "collectPodLabels":false,
    "proxy":null,
    "taskName":null,
    "gkeAutopilot":false
}
</code></pre><p><strong>New (in release 30.02)</strong></p><p>From 30.02, you can set the following values for container runtime:</p><ul><li>containerd</li><li>crio</li><li>docker</li></ul><p>Example request schema showing <strong>cri</strong> is replaced with <strong>containerRuntime</strong>:</p><pre><code>{
    "consoleAddr":"171.23.0.1",
    "namespace":"twistlock",
    "orchestration":"kubernetes",
    "selinux":false,
    "containerRuntime":"containerd",
    "privileged":false,
    "serviceAccounts":true,
    "istio":false,
    "collectPodLabels":false,
    "proxy":null,
    "taskName":null,
    "gkeAutopilot":false
}
</code></pre><p>You must update existing scripts that use either of the two endpoints when you upgrade to 30.02 or a future release.</p></td></tr></tbody></table>

## Deprecation Notice

| **Cloud Native Network Segmentation (CNNS) Deprecation** | <p>The ability to create CNNS policies that Defenders use to limit traffic from containers and hosts is being deprecated. The configuration settings on the console (<strong>Compute > Defend > CNNS</strong>) and the corresponding APIs for CNNS will be removed in the next major release. Radar has a container and a host view, where you can view the network topology for your containerized apps and hosts respectively, and this will continue to be available.</p><p>List of deprecated API endpoints:</p><ul><li>PUT, <code>/api/v\<VERSION>/policies/firewall/network/container</code></li><li>GET, <code>/api/v\<VERSION>/policies/firewall/network</code></li><li>GET, <code>/api/v\<VERSION>/audits/firewall/network/container/download</code></li><li>GET, <code>/api/v\<VERSION>/audits/firewall/network/container</code></li><li>GET, <code>/api/v\<VERSION>/audits/firewall/network/host/download</code></li><li>GET, <code>/api/v\<VERSION>/audits/firewall/network/host</code></li></ul> |
| -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Macros for Runtime Events Webhooks**                   | The `aggregated` and `rest` macros will be deprecated. For the [existing webhook alerts](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/alerts/webhook), you can edit the custom JSON body and replace `#aggregated` macro with `#aggregatedAlerts` and `#rest` macro with `#dropped`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-compute-release-information/features-introduced-in-compute-june-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
