Well for a start you have to stop a GCE instance to add a new scope to it. So if your devs want to use a new API and you're running a massive production K8s cluster, you somehow have to stop your instances to add the new scope and otherwise mess around. Of course if you know this in advance you can plan to do blue-green deployments with K8s, but if you don't know that you won't architect for it and it'll bite you.
Their authentication in general seems convoluted and complicated, their console is slow and useless (why aren't all the search results preloaded? I type in 'iam' and it takes several seconds for the results to appear). Oh, and also alpha K8s clusters will terminate after 30 days whether you like it or not (perhaps you're using a feature that's apparently stable but languishing in alpha - I'm looking at you, cronjob). There's a lack of services in general (an elasticache type service would be nice) and development seems to move glacially.
Also, they seem to have multiple versions of SDKs, some with outstanding bugs that were reported years ago but are just closed or there are comments in the README that only critical bugs will be addressed. There's no indication which SDK to use where there are several versions. Oh, and if you only want to use one service in python, you have to install about 40 different packages because splitting them up is too difficult.
We've had DFP buckets have their configs get screwed up so we mysteriously couldn't access them, logs stopped being delivered, etc. Apparently Google have such poor monitoring that we had to prompt them about these things which took too longer to get resolved. I could go on...