Eventarc 中的监管支持

本文档介绍了 Eventarc 中与受支持的控制软件包的控制相一致的功能、配置和 API。本文档假定您使用的是 Assured Workloads

ITAR 的数据边界

支持的服务

下表列出了符合 ITAR 数据边界要求的 Eventarc API 和版本。

服务 版本 状态
eventarc.googleapis.com v1 支持

支持合规性功能的区域

以下 Google Cloud 区域为 ITAR 数据边界提供 Eventarc:

  • us-central1
  • us-central2
  • us-east1
  • us-east4
  • us-east5
  • us-south1
  • us-west1
  • us-west2
  • us-west3
  • us-west4

不适合用于敏感数据的字段

下表列出了不适合包含敏感信息的字段类别和特定字段,以供参考。为确保合规性,请避免在这些字段中放置受保护的数据。如需查看完整列表,请与您的 Google Cloud 代表联系。

类别 字段
身份验证和授权
  • channel.cryptoKeyName
  • googleApiSource.cryptoKeyName
  • kafkaSource.authenticationConfig.saslAuth.usernameSecret
  • pipeline.destinations.authenticationConfig.oauthToken.scope
  • trigger.serviceAccount
分页和过滤
  • filter
  • orderBy
  • pageToken
父级资源规范
  • parent
资源配置 - 渠道
  • channel.provider
  • channelConnection.activationToken
  • channelConnection.channel
资源配置 - 注册
  • enrollment.celMatch
  • enrollment.destination
  • enrollment.messageBus
资源配置 - 流水线
  • pipeline.destinations.topic
  • pipeline.destinations.workflow
  • pipeline.inputPayloadFormat.protobuf.schemaDefinition
资源配置 - 来源
  • googleApiSource.destination
  • kafkaSource.brokerUris
  • kafkaSource.topics
资源配置 - 触发器
  • trigger.destination.cloudRun.service
  • trigger.destination.gke.cluster
  • trigger.eventFilters.attribute
资源标识
  • channelId
  • enrollmentId
  • googleApiSourceId
  • kafkaSourceId
  • messageBusId
  • pipelineId
资源命名
  • channel.name
  • enrollment.name
  • googleApiSource.name
  • kafkaSource.name
  • messageBus.name
  • name

后续步骤