Google 会使用 AI 技术将内容翻译成您偏好的语言。AI 翻译可能包含错误。
Cloud Run 中的监管支持
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
本文档介绍了 Cloud Run 中与受支持的控制措施套餐的控制措施相符的功能、配置和 API。本文档假定您使用的是 Assured Workloads。
|
ITAR 的数据边界
支持的服务
下表列出了符合 ITAR 数据边界要求的 Cloud Run API 和版本。
| 服务 |
版本 |
状态 |
| run.googleapis.com |
v1 |
支持
|
| run.googleapis.com |
v2 |
支持
|
支持合规性功能的区域
Cloud Run 可在以下 Google Cloud 区域使用,以满足 ITAR 数据边界要求:
- us-central1
- us-central2
- us-east1
- us-east4
- us-east5
- us-south1
- us-west1
- us-west2
- us-west3
- us-west4
敏感数据的 API 字段
资源:run.googleapis.com/Service
下表列出了旨在处理受 ITAR 数据边界保护的数据的 API 资源和字段。
| API 方法 |
受保护的字段 |
|
服务:run.googleapis.com
REST API:PATCH /v2/{service.name=projects/*/locations/*/services/*}
远程过程调用 (RPC) 方法:
google.cloud.run.v2.Services.UpdateService
|
service.template.containers.sourceCode.inlinedSource.sources.content
service.template.containers.sourceCode.inlinedSource.sources.filename
|
|
服务:run.googleapis.com
REST API:POST /v2/{parent=projects/*/locations/*}/services
远程过程调用 (RPC) 方法:
google.cloud.run.v2.Services.CreateService
|
service.template.containers.sourceCode.inlinedSource.sources.content
service.template.containers.sourceCode.inlinedSource.sources.filename
|
不适合用于敏感数据的字段
下表列出了不适合包含敏感信息的字段类别和特定字段,以供参考。为确保合规性,请避免在这些字段中放置受保护的数据。如需查看完整列表,请与您的 Google Cloud 代表联系。
| 类别 |
字段 |
| 容器配置 - 命令和实参 |
job.spec.template.spec.template.spec.containers.args
job.spec.template.spec.template.spec.containers.command
overrides.containerOverrides.args
service.spec.template.spec.containers.command
workerPool.spec.template.spec.containers.args
workerPool.spec.template.spec.containers.command
|
| 容器配置 - 环境变量 |
job.spec.template.spec.template.spec.containers.env.valueFrom.configMapKeyRef.name
job.spec.template.spec.template.spec.containers.env.valueFrom.secretKeyRef.name
overrides.containerOverrides.env.valueFrom.configMapKeyRef.localObjectReference.name
overrides.containerOverrides.env.valueFrom.configMapKeyRef.name
overrides.containerOverrides.env.valueFrom.secretKeyRef.localObjectReference.name
overrides.containerOverrides.env.valueFrom.secretKeyRef.name
|
| 容器配置 - 映像和资源 |
buildpackBuild.baseImage
job.spec.template.spec.template.spec.containers.image
job.spec.template.spec.template.spec.containers.resources.limits.key
job.spec.template.spec.template.spec.containers.resources.requests.key
workerPool.spec.template.spec.containers.image
workerPool.spec.template.spec.containers.resources.limits.key
|
| 容器配置 - 网络和探测 |
job.spec.template.spec.template.spec.containers.livenessProbe.httpGet.host
job.spec.template.spec.template.spec.containers.ports.name
job.spec.template.spec.template.spec.containers.readinessProbe.httpGet.host
workerPool.spec.template.spec.containers.livenessProbe.httpGet.host
workerPool.spec.template.spec.containers.ports.name
workerPool.spec.template.spec.containers.readinessProbe.httpGet.host
|
| 容器配置 - Secret 和 ConfigMap |
job.spec.template.spec.template.spec.containers.envFrom.configMapRef.localObjectReference.name
job.spec.template.spec.template.spec.containers.envFrom.configMapRef.name
job.spec.template.spec.template.spec.containers.envFrom.secretRef.localObjectReference.name
job.spec.template.spec.template.spec.containers.envFrom.secretRef.name
workerPool.spec.template.spec.containers.envFrom.configMapRef.name
workerPool.spec.template.spec.containers.envFrom.secretRef.name
|
| 容器配置 - 卷 |
job.spec.template.spec.template.spec.volumes.configMap.items.key
job.spec.template.spec.template.spec.volumes.configMap.name
job.spec.template.spec.template.spec.volumes.secret.items.key
job.spec.template.spec.template.spec.volumes.secret.secretName
workerPool.spec.template.spec.volumes.secret.items.key
workerPool.spec.template.spec.volumes.secret.secretName
|
| 过滤和分页 |
fieldSelector
filter
labelSelector
continue
|
| 元数据和注释 |
domainMapping.metadata.annotations.key
domainMapping.metadata.annotations.value
job.metadata.annotations.key
job.metadata.annotations.value
service.metadata.annotations.key
service.metadata.annotations.value
|
| 运营控制 |
dryRun
operationId
propagationPolicy
|
| 资源标识 |
apiVersion
kind
name
parent
region
serviceId
|
|
后续步骤
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2026-09-19。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2026-09-19。"],[],[]]